Input validation error in Eclipse Mosquitto - CVE-2018-12551

 

Input validation error in Eclipse Mosquitto - CVE-2018-12551

Published: February 11, 2019


Vulnerability identifier: #VU17467
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12551
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass password authentication.

The vulnerability exists due to insufficient validation of malformed input in a password file, when it is used for authentication. Incorrect data in password file will be treated by the application as a username with empty password, allowing attacker to gain unauthorized access to the application.


Affected software

Eclipse Mosquitto
mosquitto (Alpine package)
mosquitto (Debian package)
mosquitto
Fedora
Opensuse
SUSE Linux

How to mitigate CVE-2018-12551

Install updates from vendor's website.

Eclipse Mosquitto - update to 1.5.6
mosquitto (Alpine package) - update to 1.4.15-r1
mosquitto (Debian package) - update to 1.4.10-3+deb9u3
mosquitto - addressed in versions 1.5.6-1.el7, 1.5.6-1.fc28, 1.5.6-1.fc29

External References

Related Security Bulletins