PT-2018-8421 · Eclipse+1 · Eclipse Mosquitto+1
Roger Light
·
Published
2018-04-25
·
Updated
2019-10-09
·
CVE-2017-7652
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Eclipse Mosquitto version 1.4.14
Description
The issue occurs when a Mosquitto instance is running with a configuration file and a HUP signal is sent to the server, triggering a configuration reload from disk. If there are numerous clients connected, exhausting the available file descriptors/sockets (typically 1024 on Linux), the configuration file cannot be opened.
Recommendations
For Eclipse Mosquitto version 1.4.14, consider increasing the file descriptor limit to prevent exhaustion when numerous clients are connected, or implement a mechanism to handle the reload of the configuration file without requiring additional file descriptors. As a temporary workaround, consider restricting the number of clients that can connect to the server to prevent file descriptor exhaustion when the configuration is reloaded.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Eclipse Mosquitto