CVE-2023-5632
CVSS V2 None
CVSS V3 None
Description
In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data causes the EPOLLOUT event to be added, which results excessive CPU consumption. This could be used by a malicious actor to perform denial of service type attack. This issue is fixed in 2.0.6
Overview
- CVE ID
- CVE-2023-5632
- Assigner
- eclipse
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-10-18T08:34:34.788Z
- Last Modified Date
- 2023-10-18T08:34:34.788Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/eclipse/mosquitto/pull/2053 | patch issue-tracking |
https://github.com/eclipse/mosquitto/commit/18bad1ff32435e523d7507e9b2ce0010124a8f2d | patch |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-5632 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5632 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 04:56:14 | Added to TrackCVE |