• CVE-2024-3935

发布时间: 2024年11月8日

修改时间: 2024年11月13日

概要

In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming topic configured that makes use of topic remapping, then if the remote connection sends a crafted PUBLISH packet to the broker a double free will occur with a subsequent crash of the broker.

CVSS v3 指标

NVD openEuler
Confidentiality None
Attack Vector Network
CVSS评分 N/A 7.5
Attack Complexity Low
Privileges Required None
Scope Unchanged
Integrity None
User Interaction None
Availability High

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-4079 mosquitto security update 2024年11月20日
KylinSec-SA-2024-4988 mosquitto security update 2025年2月17日

影响产品

产品 状态
KY3.4-5A mosquitto Affected
KY3.5.2 mosquitto Fixed
KY3.5.3 mosquitto Fixed
V6 mosquitto Fixed