#VU100208 Double free in Eclipse Mosquitto - CVE-2024-3935
Published: November 11, 2024
Eclipse Mosquitto
Eclipse
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a double free error when a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming topic configured that makes use of topic remapping. A remote attacker can send specially crafted PUBLISH packet to the application and perform a denial of service (DoS) attack.