CVE-2019-11779
published 2019-09-19CVE-2019-11779: In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
2.74%
84.5th percentile
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | mosquitto | < mosquitto 1.6.6-1 (bookworm) | mosquitto 1.6.6-1 (bookworm) |
| eclipse | mosquitto | >= 0 < 1.6.6-1 | 1.6.6-1 |
| eclipse | mosquitto | >= 0 < 1.6.6-1 | 1.6.6-1 |
| eclipse | mosquitto | >= 0 < 1.6.6-1 | 1.6.6-1 |
| eclipse | mosquitto | >= 0 < 1.6.6-1 | 1.6.6-1 |
| eclipse | mosquitto | >= 1.5 < 1.5.9 | 1.5.9 |
| eclipse | mosquitto | >= 1.6 < 1.6.6 | 1.6.6 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| the_eclipse_foundation | eclipse_mosquitto | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wjwr-9f4q-q8h8: In Eclipse Mosquitto 1
ghsa_unreviewed·2022-05-24
CVE-2019-11779 [MEDIUM] CWE-674 GHSA-wjwr-9f4q-q8h8: In Eclipse Mosquitto 1
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.
OSV
CVE-2019-11779: In Eclipse Mosquitto 1
osv·2019-09-19·CVSS 6.5
CVE-2019-11779 [MEDIUM] CVE-2019-11779: In Eclipse Mosquitto 1
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.
Ubuntu
Mosquitto vulnerability
vendor_ubuntu·2019-09-23
CVE-2019-11779 Mosquitto vulnerability
Title: Mosquitto vulnerability
Summary: Mosquitto could be made to crash or run programs if it received
specially crafted network traffic.
It was discovered that Mosquitto incorrectly handled certain specially crafted
input and network packets. A remote attacker could use this to cause a denial
of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-11779: mosquitto - In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends ...
vendor_debian·2019·CVSS 6.5
CVE-2019-11779 [MEDIUM] CVE-2019-11779: mosquitto - In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends ...
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.
Scope: local
bookworm: resolved (fixed in 1.6.6-1)
bullseye: resolved (fixed in 1.6.6-1)
forky: resolved (fixed in 1.6.6-1)
sid: resolved (fixed in 1.6.6-1)
trixie: resolved (fixed in 1.6.6-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-11779 mosquitto: malicious MQTT sends SUBSCRIBE packet leads to stack over flow [epel-7]
bugzilla·2019-09-20·CVSS 6.5
CVE-2019-11779 [MEDIUM] CVE-2019-11779 mosquitto: malicious MQTT sends SUBSCRIBE packet leads to stack over flow [epel-7]
CVE-2019-11779 mosquitto: malicious MQTT sends SUBSCRIBE packet leads to stack over flow [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following templ
Bugzilla
CVE-2019-11779 mosquitto: malicious MQTT sends SUBSCRIBE packet leads to stack over flow
bugzilla·2019-09-20·CVSS 6.5
CVE-2019-11779 [MEDIUM] CVE-2019-11779 mosquitto: malicious MQTT sends SUBSCRIBE packet leads to stack over flow
CVE-2019-11779 mosquitto: malicious MQTT sends SUBSCRIBE packet leads to stack over flow
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.
Reference:
https://bugs.eclipse.org/bugs/show_bug.cgi?id=551160
Discussion:
Created mosquitto tracking bugs for this issue:
Affects: epel-7 [bug 1753848]
Affects: fedora-all [bug 1753847]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
Bugzilla
CVE-2019-11779 mosquitto: malicious MQTT sends SUBSCRIBE packet leads to stack over flow [fedora-all]
bugzilla·2019-09-20·CVSS 6.5
CVE-2019-11779 [MEDIUM] CVE-2019-11779 mosquitto: malicious MQTT sends SUBSCRIBE packet leads to stack over flow [fedora-all]
CVE-2019-11779 mosquitto: malicious MQTT sends SUBSCRIBE packet leads to stack over flow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00077.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00008.htmlhttps://bugs.eclipse.org/bugs/show_bug.cgi?id=551160https://lists.debian.org/debian-lts-announce/2019/10/msg00035.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D4WMHIM64Q35NGTR6R3ILZUL4MA4ANB5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HFWQBNFTAVHPUYNGYO2TCPF5PCSWC2Z7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWNVTFA2CKXERXRYPYE2YFTZP4GNBGYY/https://seclists.org/bugtraq/2019/Nov/25https://usn.ubuntu.com/4137-1/https://www.debian.org/security/2019/dsa-4570http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00077.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00008.htmlhttps://bugs.eclipse.org/bugs/show_bug.cgi?id=551160https://lists.debian.org/debian-lts-announce/2019/10/msg00035.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D4WMHIM64Q35NGTR6R3ILZUL4MA4ANB5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HFWQBNFTAVHPUYNGYO2TCPF5PCSWC2Z7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWNVTFA2CKXERXRYPYE2YFTZP4GNBGYY/https://seclists.org/bugtraq/2019/Nov/25https://usn.ubuntu.com/4137-1/https://www.debian.org/security/2019/dsa-4570
2019-09-19
Published