In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming topic configured that makes use of topic remapping, then if the remote connection sends a crafted PUBLISH packet to the broker a double free will occur with a subsequent crash of the broker.
History

Thu, 31 Oct 2024 09:30:00 +0000


Wed, 30 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Eclipse Foundation
Eclipse Foundation mosquitto
CPEs cpe:2.3:a:eclipse_foundation:mosquitto:*:*:*:*:*:*:*:*
Vendors & Products Eclipse Foundation
Eclipse Foundation mosquitto
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Oct 2024 12:00:00 +0000

Type Values Removed Values Added
Description In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming topic configured that makes use of topic remapping, then if the remote connection sends a crafted PUBLISH packet to the broker a double free will occur with a subsequent crash of the broker.
Title Eclipse Mosquito: Double free vulnerability
Weaknesses CWE-415
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published: 2024-10-30T11:45:23.506Z

Updated: 2024-10-31T09:12:11.012Z

Reserved: 2024-04-17T17:12:36.491Z

Link: CVE-2024-3935

cve-icon Vulnrichment

Updated: 2024-10-30T13:32:01.043Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-30T12:15:03.090

Modified: 2024-11-01T12:57:03.417

Link: CVE-2024-3935

cve-icon Redhat

No data.