In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade mosquitto | Nov 8, 2019 | Sep 19, 2019 |
| Debian | — | Upgrade mosquitto | Oct 28, 2019 | Sep 19, 2019 |
| Suse | — | Upgrade mosquitto-develUpgrade libmosquitto1Upgrade mosquitto-clientsUpgrade libmosquittopp1Upgrade mosquitto | Sep 29, 2019 | Sep 19, 2019 |
| Ubuntu | — | Upgrade libmosquitto1Upgrade mosquitto-clientsUpgrade mosquittoUpgrade libmosquittopp1 | Sep 24, 2019 | Sep 19, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub