Project

General

Profile

Actions

Security #5399

closed
PA OD

mqtt: DOS by quadratic with too many transactions in one parse

Security #5399: mqtt: DOS by quadratic with too many transactions in one parse

Added by Philippe Antoine almost 4 years ago. Updated over 3 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Label:
CVE:
Git IDs:
Severity:
MODERATE
Disclosure Date:

Subtasks 1 (0 open1 closed)

Security #5430: mqtt: DOS by quadratic with too many transactions in one parse (6.0.x backport)ClosedJeff LucovskyActions

Related issues 1 (0 open1 closed)

Related to Suricata - Bug #4530: DOS Quadratic complexity when having too many transactionsClosedPhilippe AntoineActions

PA Updated by Philippe Antoine almost 4 years ago Actions #1

  • Status changed from New to Assigned
  • Target version changed from TBD to 7.0.0-beta1
  • Affected Versions 6.0.5 added
  • Label Needs backport, Needs backport to 6.0 added

Fouad by oss-fuzz:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47934

One transaction is created out of 2 bytes when calling parsing with a 400 000 bytes input

PA Updated by Philippe Antoine almost 4 years ago Actions #2

  • Related to Bug #4530: DOS Quadratic complexity when having too many transactions added

PA Updated by Philippe Antoine almost 4 years ago Actions #3

  • Status changed from Assigned to In Review

Gitlab

VJ Updated by Victor Julien almost 4 years ago Actions #4

  • Label deleted (Needs backport, Needs backport to 6.0)

VJ Updated by Victor Julien over 3 years ago Actions #5

  • Tracker changed from Bug to Security
  • Severity set to MODERATE

PA Updated by Philippe Antoine over 3 years ago Actions #6

  • Status changed from In Review to Resolved

PA Updated by Philippe Antoine over 3 years ago Actions #7

  • Status changed from Resolved to Closed

VJ Updated by Victor Julien over 3 years ago Actions #8

  • Private changed from Yes to No
Actions

Also available in: PDF Atom