#VU51973 NULL pointer dereference in Eclipse Mosquitto - CVE-2021-28166
Published: April 8, 2021
Eclipse Mosquitto
Eclipse
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in Eclipse Mosquitto when processing CONNACK messages. A remote authenticated user connected with MQTT v5 can send a specially crafted CONNACK message to the broker, trigger a NULL pointer dereference error and crash the service.