CVE-2021-34431
Summary
| CVE | CVE-2021-34431 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-22 14:15:00 UTC |
| Updated | 2021-08-03 17:49:00 UTC |
| Description | In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur, which could be used to provide a DoS attack against the broker. |
Risk And Classification
Problem Types: CWE-401
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 573191 – (CVE-2021-34431) Possible DoS through Memory Leak in Mosquitto Broker | CONFIRM | bugs.eclipse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Thanks to Kathrin Kleinhammer of OTARIS Interactive Services GmbH for discovering and reporting this issue.