{
  "threat_severity" : "Moderate",
  "public_date" : "2023-09-01T00:00:00Z",
  "bugzilla" : {
    "description" : "mosquitto: memory leak leads to unresponsive broker",
    "id" : "2236882",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2236882"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-401",
  "details" : [ "In Mosquitto before 2.0.16, a memory leak occurs when clients send v5 CONNECT packets with a will message that contains invalid property types.", "A memory leak vulnerability was found in Eclipse Mosquitto. This issue is triggered by malicious initial packets or certain client actions and may allow a remote attacker to the deplete system resources causing memory exhaustion, leading to a disruption in services and a denial of service condition." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Satellite 6.13 for RHEL 8",
    "release_date" : "2024-02-29T00:00:00Z",
    "advisory" : "RHSA-2024:1061",
    "cpe" : "cpe:/a:redhat:satellite:6.13::el8",
    "package" : "mosquitto-0:2.0.17-1.el8sat"
  }, {
    "product_name" : "Red Hat Satellite 6.13 for RHEL 8",
    "release_date" : "2024-02-29T00:00:00Z",
    "advisory" : "RHSA-2024:1061",
    "cpe" : "cpe:/a:redhat:satellite_capsule:6.13::el8",
    "package" : "mosquitto-0:2.0.17-1.el8sat"
  }, {
    "product_name" : "Red Hat Satellite 6.14 for RHEL 8",
    "release_date" : "2024-02-13T00:00:00Z",
    "advisory" : "RHSA-2024:0797",
    "cpe" : "cpe:/a:redhat:satellite:6.14::el8",
    "package" : "mosquitto-0:2.0.17-1.el8sat"
  }, {
    "product_name" : "Red Hat Satellite 6.14 for RHEL 8",
    "release_date" : "2024-02-13T00:00:00Z",
    "advisory" : "RHSA-2024:0797",
    "cpe" : "cpe:/a:redhat:satellite_capsule:6.14::el8",
    "package" : "mosquitto-0:2.0.17-1.el8sat"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat build of Apache Camel for Spring Boot 3",
    "fix_state" : "Not affected",
    "package_name" : "mosquitto",
    "cpe" : "cpe:/a:redhat:camel_spring_boot:3"
  }, {
    "product_name" : "Red Hat Integration Camel K 1",
    "fix_state" : "Not affected",
    "package_name" : "mosquitto",
    "cpe" : "cpe:/a:redhat:integration:1"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2023-3592\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-3592\nhttps://github.com/eclipse/mosquitto/commit/6113eac95a9df634fbc858be542c4a0456bfe7b9" ],
  "name" : "CVE-2023-3592",
  "csaw" : false
}