CVE-2024-3935

In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming topic configured that makes use of topic remapping, then if the remote connection sends a crafted PUBLISH packet to the broker a double free will occur with a subsequent crash of the broker.
Configurations

Configuration 1 (hide)

cpe:2.3:a:eclipse:mosquitto:*:*:*:*:*:*:*:*

History

29 Jan 2025, 17:12

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:eclipse:mosquitto:*:*:*:*:*:*:*:*
CWE CWE-415
First Time Eclipse
Eclipse mosquitto
References () https://mosquitto.org/blog/2024/10/version-2-0-19-released/ - () https://mosquitto.org/blog/2024/10/version-2-0-19-released/ - Release Notes
References () https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/197 - () https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/197 - Exploit, Issue Tracking, Vendor Advisory
References () https://github.com/eclipse-mosquitto/mosquitto/commit/ae7a804dadac8f2aaedb24336df8496a9680fda9 - () https://github.com/eclipse-mosquitto/mosquitto/commit/ae7a804dadac8f2aaedb24336df8496a9680fda9 - Patch

31 Oct 2024, 10:15

Type Values Removed Values Added
References
  • () https://github.com/eclipse-mosquitto/mosquitto/commit/ae7a804dadac8f2aaedb24336df8496a9680fda9 -

30 Oct 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-30 12:15

Updated : 2025-01-29 17:12


NVD link : CVE-2024-3935

Mitre link : CVE-2024-3935


JSON object : View

Products Affected

eclipse

  • mosquitto
CWE
CWE-415

Double Free