In Eclipse Mosquitto 1.4.15 and earlier, a Memory Leak vulnerability was found within the Mosquitto Broker. Unauthenticated clients can send crafted CONNECT packets which could cause a denial of service in the Mosquitto Broker.
The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mosquitto | Eclipse | * | 1.4.15 (including) |
Mosquitto | Ubuntu | artful | * |
Mosquitto | Ubuntu | bionic | * |
Mosquitto | Ubuntu | cosmic | * |
Mosquitto | Ubuntu | esm-infra-legacy/trusty | * |
Mosquitto | Ubuntu | trusty | * |
Mosquitto | Ubuntu | trusty/esm | * |
Mosquitto | Ubuntu | upstream | * |
Mosquitto | Ubuntu | xenial | * |