CVE-2024-3935

In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming topic configured that makes use of topic remapping, then if the remote connection sends a crafted PUBLISH packet to the broker a double free will occur with a subsequent crash of the broker.
Configurations

No configuration.

History

31 Oct 2024, 10:15

Type Values Removed Values Added
References
  • () https://github.com/eclipse-mosquitto/mosquitto/commit/ae7a804dadac8f2aaedb24336df8496a9680fda9 -

30 Oct 2024, 14:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
Summary
  • (es) En Eclipse Mosquito, versiones desde 2.0.0 hasta 2.0.18, si un agente Mosquitto está configurado para crear una conexión de puente saliente y esa conexión de puente tiene un tema entrante configurado que hace uso de reasignación de temas, entonces si la conexión remota envía un paquete PUBLISH manipulado al agente, se producirá una doble liberación con un bloqueo posterior del agente.

30 Oct 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-30 12:15

Updated : 2024-11-01 12:57


NVD link : CVE-2024-3935

Mitre link : CVE-2024-3935

CVE.ORG link : CVE-2024-3935


JSON object : View

Products Affected

No product.

CWE
CWE-415

Double Free