CVE-2019-11778

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
18/09/2019
Last modified:
09/10/2019

Description

If an MQTT v5 client connects to Eclipse Mosquitto versions 1.6.0 to 1.6.4 inclusive, sets a last will and testament, sets a will delay interval, sets a session expiry interval, and the will delay interval is set longer than the session expiry interval, then a use after free error occurs, which has the potential to cause a crash in some situations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclipse:mosquitto:*:*:*:*:*:*:*:* 1.6 (including) 1.6.5 (excluding)


References to Advisories, Solutions, and Tools