CVE-2024-8376

In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.
Configurations

Configuration 1 (hide)

cpe:2.3:a:eclipse:mosquitto:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-10-11 16:15

Updated : 2024-11-15 17:21


NVD link : CVE-2024-8376

Mitre link : CVE-2024-8376

CVE.ORG link : CVE-2024-8376


JSON object : View

Products Affected

eclipse

  • mosquitto
CWE
CWE-401

Missing Release of Memory after Effective Lifetime

CWE-416

Use After Free

CWE-755

Improper Handling of Exceptional Conditions