Resource exhaustion in Eclipse Mosquitto - CVE-2017-7651
Published: April 24, 2018 / Updated: August 3, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with large payload. This can be done without authentications if occur in connection phase of MQTT protocol.
Affected software
mosquitto (Alpine package)
mosquitto
Fedora
How to mitigate CVE-2017-7651
mosquitto (Alpine package) - update to 1.4.15-r0
mosquitto - addressed in versions 1.4.15-1.el7, 1.4.15-1.fc26, 1.4.15-1.fc27, 1.4.15-1.fc28
External References
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=529754
- https://lists.debian.org/debian-lts-announce/2018/03/msg00037.html
- https://lists.debian.org/debian-lts-announce/2018/06/msg00016.html
- https://mosquitto.org/blog/2018/02/security-advisory-cve-2017-7651-cve-2017-7652/
- https://www.debian.org/security/2018/dsa-4325