Bug ID | 1193322 |
---|---|
Summary | VUL-1: CVE-2021-41039: In versions 1.6 to 2.0.11 of Eclipse Mosquitto, a client connecting with a large number of user-property properties could cause DoS |
Classification | openSUSE |
Product | openSUSE Distribution |
Version | Leap 15.2 |
Hardware | Other |
URL | https://smash.suse.de/issue/316157/ |
OS | Other |
Status | NEW |
Severity | Minor |
Priority | P5 - None |
Component | Security |
Assignee | mardnh@gmx.de |
Reporter | carlos.lopez@suse.com |
QA Contact | security-team@suse.de |
Found By | Security Response Team |
Blocker | --- |
CVE-2021-41039 In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property properties could cause excessive CPU usage, leading to a loss of performance and possible denial of service. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-41039 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41039 https://bugs.eclipse.org/bugs/show_bug.cgi?id=575314