Input validation error in Eclipse Mosquitto - CVE-2018-12551
Published: February 11, 2019
Vulnerability details
The vulnerability allows a remote attacker to bypass password authentication.
The vulnerability exists due to insufficient validation of malformed input in a password file, when it is used for authentication. Incorrect data in password file will be treated by the application as a username with empty password, allowing attacker to gain unauthorized access to the application.
Affected software
mosquitto (Alpine package)
mosquitto (Debian package)
mosquitto
Fedora
Opensuse
SUSE Linux
How to mitigate CVE-2018-12551
mosquitto (Alpine package) - update to 1.4.15-r1
mosquitto (Debian package) - update to 1.4.10-3+deb9u3
mosquitto - addressed in versions 1.5.6-1.el7, 1.5.6-1.fc28, 1.5.6-1.fc29