CVE-2021-34432Improper Input Validation in Eclipse Foundation Eclipse Mosquitto

Severity
7.5HIGHNVD
EPSS
0.3%
top 43.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 27
Latest updateMay 24

Description

In Eclipse Mosquitto versions 2.07 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Debianeclipse/mosquitto< 2.0.8-1+3
CVEListV5the_eclipse_foundation/eclipse_mosquittounspecified2.07

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9972-xmxv-v66x: In Eclipse Mosquitto versions 22022-05-24
OSV
CVE-2021-34432: In Eclipse Mosquitto versions 22021-07-27
CVEList
CVE-2021-34432: In Eclipse Mosquitto versions 22021-07-27

📋Vendor Advisories

1
Debian
CVE-2021-34432: mosquitto - In Eclipse Mosquitto versions 2.07 and earlier, the server will crash if the cli...2021
CVE-2021-34432 — Improper Input Validation | cvebase