Eclipse Mosquito: Heap Buffer Overflow in my_subscribe_callback
Vulnerability Description
In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-10525
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Qingpeng Du
References
More from Eclipse Foundation
View All →Affected Vendor
Eclipse Foundation
View all reports →