Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 918540 (CVE-2023-0809, CVE-2023-28366, CVE-2023-3592) - <app-misc/mosquitto-2.0.17: multiple vulnerabilities
Summary: <app-misc/mosquitto-2.0.17: multiple vulnerabilities
Status: CONFIRMED
Alias: CVE-2023-0809, CVE-2023-28366, CVE-2023-3592
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://mosquitto.org/blog/2023/08/ve...
Whiteboard: B3 [stable]
Keywords:
Depends on: 916239
Blocks:
  Show dependency tree
 
Reported: 2023-11-25 17:51 UTC by John Helmert III
Modified: 2023-11-25 17:52 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-11-25 17:51:22 UTC
CVE-2023-28366:

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.

CVE-2023-0809:

In Mosquitto before 2.0.16, excessive memory is allocated based on malicious initial packets that are not CONNECT packets.

CVE-2023-3592:

In Mosquitto before 2.0.16, a memory leak occurs when clients send v5 CONNECT packets with a will message that contains invalid property types.


Please stabilize >2.0.16.