eclipse mosquitto CVE-2017-7655 in Eclipse and Debian Products
Published on March 27, 2019

product logo product logo
In Eclipse Mosquitto version from 1.0 to 1.4.15, a Null Dereference vulnerability was found in the Mosquitto library which could lead to crashes for those applications using the library.

NVD

Weakness Type

NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit. NULL pointer dereference issues can occur through a number of flaws, including race conditions, and simple programming omissions.


Products Associated with CVE-2017-7655

stack.watch emails you whenever new vulnerabilities are published in Eclipse Mosquitto or Debian Linux. Just hit a watch button to start following.

 
 

Affected Versions

The Eclipse Foundation Eclipse Mosquitto:

Exploit Probability

EPSS
0.87%
Percentile
74.97%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.