CVE-2017-7652 — Memory Allocation with Excessive Size Value in Mosquitto
Severity
7.5HIGHNVD
EPSS
1.0%
top 22.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 25
Latest updateMay 13
Description
In Eclipse Mosquitto 1.4.14, if a Mosquitto instance is set running with a configuration file, then sending a HUP signal to server triggers the configuration to be reloaded from disk. If there are lots of clients connected so that there are no more file descriptors/sockets available (default limit typically 1024 file descriptors on Linux), then opening the configuration file will fail.
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9
Affected Packages3 packages
Also affects: Debian Linux 7.0, 8.0, 9.0
Patches
🔴Vulnerability Details
3📋Vendor Advisories
1Debian▶
CVE-2017-7652: mosquitto - In Eclipse Mosquitto 1.4.14, if a Mosquitto instance is set running with a confi...↗2017
💬Community
4Bugzilla▶
CVE-2017-7652 mosquitto: configuration reload fails when no free sockets/file descriptors are available [fedora-all]↗2018-03-05
Bugzilla▶
CVE-2017-7652 mosquitto: configuration reload fails when no free sockets/file descriptors are available [epel-7]↗2018-03-05
Bugzilla
▶
Bugzilla▶
CVE-2017-7652 mosquitto: configuration reload fails when no free sockets/file descriptors are available↗2018-03-05