CVE-2017-7653

Publication date 5 June 2018

Last updated 26 August 2025


Ubuntu priority

Cvss 3 Severity Score

5.3 · Medium

Score breakdown

Description

The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8. A malicious client could cause other clients that do reject invalid UTF-8 strings to disconnect themselves from the broker by sending a topic string which is not valid UTF-8, and so cause a denial of service for the clients.

Status

Package Ubuntu Release Status
mosquitto 26.04 LTS resolute
Not affected
25.10 questing
Not affected
25.04 plucky
Not affected
24.10 oracular
Not affected
24.04 LTS noble
Not affected
23.10 mantic
Not affected
23.04 lunar
Not affected
22.10 kinetic
Not affected
22.04 LTS jammy
Not affected
21.10 impish
Not affected
21.04 hirsute
Not affected
20.10 groovy
Not affected
20.04 LTS focal
Not affected
19.10 eoan
Not affected
19.04 disco
Not affected
18.10 cosmic
Fixed 1.4.15-2ubuntu0.18.10.3
18.04 LTS bionic
Fixed 1.4.15-2ubuntu0.18.04.3
17.10 artful Ignored end of life
16.04 LTS xenial
Fixed 1.4.8-1ubuntu0.16.04.7
14.04 LTS trusty
Vulnerable

Severity score breakdown

CVSS version: CVSS v3.0

Base score 5.3 · Medium

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

References

Related Ubuntu Security Notices (USN)

    • USN-4023-1
    • Mosquitto vulnerabilities
    • 20 June 2019

Other references


Access our resources on patching vulnerabilities