Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
FlashMQ: Division by zero crash when using non-default deferred retained message setting
Vulnerability Description
FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.1, a remote client with retained publish permission can crash the FlashMQ broker when both set_retained_message_defer_timeout and set_retained_message_defer_timeout_spread are configured to non-default values, resulting in denial of service. If anonymous retained publishing is allowed, no authentication is required; otherwise, the attacker needs the corresponding publish permission. This issue has been patched in version 1.26.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
除零错误
Vulnerability Title
FlashMQ 数字错误漏洞
Vulnerability Description
FlashMQ是Wiebe Cazemier个人开发者的一个快速轻量级的MQTT代理服务器。 FlashMQ 1.26.1之前版本存在数字错误漏洞,该漏洞源于当set_retained_message_defer_timeout和set_retained_message_defer_timeout_spread配置为非默认值时,具有保留发布权限的远程客户端可能导致FlashMQ代理崩溃,导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A