Stack-based buffer overflow in Eclipse Mosquitto - CVE-2019-11779

 

Stack-based buffer overflow in Eclipse Mosquitto - CVE-2019-11779

Published: September 29, 2019


Vulnerability identifier: #VU21405
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11779
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when processing an overly long SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters. A malicious MQTT client can send a specially crafted SUBSCRIBE packet, trigger stack overflow and perform denial of service attack.


Affected software

Eclipse Mosquitto
mosquitto (Alpine package)
mosquitto (Debian package)
mosquitto
Fedora
SUSE Linux
Opensuse

How to mitigate CVE-2019-11779

Install updates from vendor's website.

Eclipse Mosquitto - addressed in versions 1.5.9, 1.6.6
mosquitto (Alpine package) - update to 1.5.6-r1
mosquitto (Debian package) - update to 1.5.7-1+deb10u1
mosquitto - addressed in versions 1.6.7-1.el7, 1.6.7-1.fc29, 1.6.7-1.fc30, 1.6.7-1.fc31

External References

Related Security Bulletins