CVE-2024-8376
CVSS V2 None
CVSS V3 None
Description
In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.
Overview
- CVE ID
- CVE-2024-8376
- Assigner
- eclipse
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-10-11T15:18:54.142Z
- Last Modified Date
- 2024-10-11T15:36:51.348Z
References
Reference URL | Reference Tags |
---|---|
https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/216 | issue-tracking |
https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/217 | issue-tracking |
https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/218 | issue-tracking |
https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/227 | issue-tracking |
https://gitlab.eclipse.org/security/cve-assignement/-/issues/26 | vendor-advisory |
https://github.com/eclipse/mosquitto/releases/tag/v2.0.19 | patch |
https://mosquitto.org/ | product |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-8376 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8376 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-10-12 13:16:36 | Added to TrackCVE |