Intelligence View
USN-7441-1: Eclipse Mosquitto vulnerabilities
It was discovered that Eclipse Mosquitto client incorrectly handled memory when receiving a SUBACK packet. An attacker with a malicious broker could possibly…
memory when receiving a SUBACK packet. An attacker with a malicious
broker could possibly use this issue to execute arbitrary code or
cause a denial of service. (CVE-2024-10525)
Xiangpu Song discovered that Eclipse Mosquitto broker did not properly
manage memory under certain circumstances. A malicious client with a
remote connection could possibly use this issue to cause the broker to
crash resulting in a denial of service, or another unspecified impact.
This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS.
(CVE-2024-3935)
Cyber Threat Intelligence & Forensik
Compliance, SLA & Vendor Adherence
Hersteller-Sicherheitsmeldungen & Patch-Status
Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.
-
Web Referencegitlab.eclipse.org
-
Web Referencemosquitto.org
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com