Resource exhaustion in Eclipse Mosquitto - CVE-2017-7651

 

Resource exhaustion in Eclipse Mosquitto - CVE-2017-7651

Published: April 24, 2018 / Updated: August 3, 2020


Vulnerability identifier: #VU33230
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7651
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with large payload. This can be done without authentications if occur in connection phase of MQTT protocol.


Affected software

Eclipse Mosquitto
mosquitto (Alpine package)
mosquitto
Fedora

How to mitigate CVE-2017-7651

Install update from vendor's website.

Eclipse Mosquitto - update to 1.4.15
mosquitto (Alpine package) - update to 1.4.15-r0
mosquitto - addressed in versions 1.4.15-1.el7, 1.4.15-1.fc26, 1.4.15-1.fc27, 1.4.15-1.fc28

External References

Related Security Bulletins