#VU21405 Stack-based buffer overflow in Eclipse Mosquitto - CVE-2019-11779
Published: September 29, 2019
Eclipse Mosquitto
Eclipse
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing an overly long SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters. A malicious MQTT client can send a specially crafted SUBSCRIBE packet, trigger stack overflow and perform denial of service attack.