CVE-2024-10525
CRITICALEclipse Mosquitto < 2.0.19 - Out-of-Bounds Write
Title source: ruleDescription
In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.
References (4)
Core 4
Core References
Patch
https://github.com/eclipse-mosquitto/mosquitto/commit/8ab20b4ba4204fdcdec78cb4d9f03c944a6e0e1c
Exploit, Issue Tracking, Vendor Advisory
https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/190
Scores
CVSS v3
9.8
EPSS
0.1751
EPSS Percentile
95.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-122
CWE-787
Status
published
Products (1)
eclipse/mosquitto
1.3.2 - 2.0.19
Published
Oct 30, 2024
Tracked Since
Feb 18, 2026