Project

General

Profile

Actions

Security #5399

closed

mqtt: DOS by quadratic with too many transactions in one parse

Added by Philippe Antoine almost 2 years ago. Updated over 1 year ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Label:
CVE:
Git IDs:
Severity:
MODERATE
Disclosure Date:

Subtasks 1 (0 open1 closed)

Security #5430: mqtt: DOS by quadratic with too many transactions in one parse (6.0.x backport)ClosedJeff LucovskyActions

Related issues 1 (0 open1 closed)

Related to Suricata - Bug #4530: DOS Quadratic complexity when having too many transactionsClosedPhilippe AntoineActions
Actions #1

Updated by Philippe Antoine almost 2 years ago

  • Status changed from New to Assigned
  • Target version changed from TBD to 7.0.0-beta1
  • Affected Versions 6.0.5 added
  • Label Needs backport, Needs backport to 6.0 added

Fouad by oss-fuzz:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47934

One transaction is created out of 2 bytes when calling parsing with a 400 000 bytes input

Actions #2

Updated by Philippe Antoine almost 2 years ago

  • Related to Bug #4530: DOS Quadratic complexity when having too many transactions added
Actions #3

Updated by Philippe Antoine almost 2 years ago

  • Status changed from Assigned to In Review

Gitlab

Actions #4

Updated by Victor Julien almost 2 years ago

  • Label deleted (Needs backport, Needs backport to 6.0)
Actions #5

Updated by Victor Julien over 1 year ago

  • Tracker changed from Bug to Security
  • Severity set to MODERATE
Actions #6

Updated by Philippe Antoine over 1 year ago

  • Status changed from In Review to Resolved
Actions #7

Updated by Philippe Antoine over 1 year ago

  • Status changed from Resolved to Closed
Actions #8

Updated by Victor Julien over 1 year ago

  • Private changed from Yes to No
Actions

Also available in: Atom PDF