The Eclipse Mosquitto broker up to version 1.4.15 does not...
Vulnerability Description
The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8. A malicious client could cause other clients that do reject invalid UTF-8 strings to disconnect themselves from the broker by sending a topic string which is not valid UTF-8, and so cause a denial of service for the clients.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-7653
Credits & Attribution
No credits recorded in the NVD database.
References
More from The Eclipse Foundation
View All →Affected Vendor
The Eclipse Foundation
View all reports →