← Back to CVE List

CVE-2024-10525

Published: 2024-10-30T12:15Z
Last Modified: 2025-01-29T17:04Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt