In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data causes the EPOLLOUT event to be added, which results excessive CPU consumption. This could be used by a malicious actor to perform denial of service type attack. This issue is fixed in 2.0.6
The product performs an iteration or loop without sufficiently limiting the number of times that the loop is executed.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mosquitto | Eclipse | * | 2.0.6 (excluding) |
Mosquitto | Ubuntu | bionic | * |
Mosquitto | Ubuntu | trusty | * |
Mosquitto | Ubuntu | upstream | * |
Mosquitto | Ubuntu | xenial | * |