ALT-PU-2020-3496-1
Closed vulnerabilities
BDU:2020-01486
Уязвимость брокера сообщений Eclipse Mosquitto, связанная с недостаточной проверкой исключительных состояний, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-11778
If an MQTT v5 client connects to Eclipse Mosquitto versions 1.6.0 to 1.6.4 inclusive, sets a last will and testament, sets a will delay interval, sets a session expiry interval, and the will delay interval is set longer than the session expiry interval, then a use after free error occurs, which has the potential to cause a crash in some situations.
Modified: 2024-11-21
CVE-2019-11779
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.
- openSUSE-SU-2019:2206
- openSUSE-SU-2019:2206
- openSUSE-SU-2019:2247
- openSUSE-SU-2019:2247
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=551160
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=551160
- [debian-lts-announce] 20191026 [SECURITY] [DLA 1972-1] mosquitto security update
- [debian-lts-announce] 20191026 [SECURITY] [DLA 1972-1] mosquitto security update
- FEDORA-2019-d99e2329cb
- FEDORA-2019-d99e2329cb
- FEDORA-2019-4c69fb4cd7
- FEDORA-2019-4c69fb4cd7
- FEDORA-2019-8b83c261dd
- FEDORA-2019-8b83c261dd
- 20191118 [SECURITY] [DSA 4570-1] mosquitto security update
- 20191118 [SECURITY] [DSA 4570-1] mosquitto security update
- USN-4137-1
- USN-4137-1
- DSA-4570
- DSA-4570