Stack-based buffer overflow in Eclipse Mosquitto - CVE-2019-11779
Published: September 29, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing an overly long SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters. A malicious MQTT client can send a specially crafted SUBSCRIBE packet, trigger stack overflow and perform denial of service attack.
Affected software
mosquitto (Alpine package)
mosquitto (Debian package)
mosquitto
Fedora
SUSE Linux
Opensuse
How to mitigate CVE-2019-11779
mosquitto (Alpine package) - update to 1.5.6-r1
mosquitto (Debian package) - update to 1.5.7-1+deb10u1
mosquitto - addressed in versions 1.6.7-1.el7, 1.6.7-1.fc29, 1.6.7-1.fc30, 1.6.7-1.fc31
External References
Related Security Bulletins
- Denial of service in Eclipse Mosquitto
- OpenSUSE Linux update for mosquitto
- OpenSUSE Linux update for mosquitto
- Debian update for mosquitto
- Stack-based buffer overflow in mosquitto (Alpine package)
- Fedora 30 update for mosquitto
- Fedora 31 update for mosquitto
- Fedora EPEL 7 update for mosquitto
- Fedora 29 update for mosquitto