cbcvebase.

Debian Mosquitto vulnerabilities

25 known vulnerabilities affecting debian/mosquitto.

Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH12MEDIUM12LOW1

Vulnerabilities

Page 2 of 2
CVE-2021-34434P4MEDIUMCVSS 5.3fixed in mosquitto 2.0.11-1.2+deb12u1 (bookworm)2021
CVE-2021-34434 [MEDIUM] CVE-2021-34434: mosquitto - In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plu... In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked. Scope: local bookworm: resolved (fixed in 2.0.11-1.2+deb12u1) bullseye: resolved (fixed in 2.0.11-1+deb11u1) for
debian
CVE-2023-0809P4MEDIUMCVSS 5.8fixed in mosquitto 2.0.11-1.2+deb12u1 (bookworm)2023
CVE-2023-0809 [MEDIUM] CVE-2023-0809: mosquitto - In Mosquitto before 2.0.16, excessive memory is allocated based on malicious ini... In Mosquitto before 2.0.16, excessive memory is allocated based on malicious initial packets that are not CONNECT packets. Scope: local bookworm: resolved (fixed in 2.0.11-1.2+deb12u1) bullseye: resolved (fixed in 2.0.11-1+deb11u1) forky: resolved (fixed in 2.0.17-1) sid: resolved (fixed in 2.0.17-1) trixie: resolved (fixed in 2.0.17-1)
debian
CVE-2019-11778P4MEDIUMCVSS 5.4fixed in mosquitto 1.6.6-1 (bookworm)2019
CVE-2019-11778 [MEDIUM] CVE-2019-11778: mosquitto - If an MQTT v5 client connects to Eclipse Mosquitto versions 1.6.0 to 1.6.4 inclu... If an MQTT v5 client connects to Eclipse Mosquitto versions 1.6.0 to 1.6.4 inclusive, sets a last will and testament, sets a will delay interval, sets a session expiry interval, and the will delay interval is set longer than the session expiry interval, then a use after free error occurs, which has the potential to cause a crash in some situations. Scope: local
debian
CVE-2017-7653P4MEDIUMCVSS 5.3fixed in mosquitto 1.5.4-1 (bookworm)2017
CVE-2017-7653 [MEDIUM] CVE-2017-7653: mosquitto - The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that a... The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8. A malicious client could cause other clients that do reject invalid UTF-8 strings to disconnect themselves from the broker by sending a topic string which is not valid UTF-8, and so cause a denial of service for the clients. Scope: local bookworm: resolved (fixed in
debian
CVE-2017-9868P4MEDIUMCVSS 5.5fixed in mosquitto 1.4.14-1 (bookworm)2017
CVE-2017-9868 [MEDIUM] CVE-2017-9868: mosquitto - In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world re... In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information. Scope: local bookworm: resolved (fixed in 1.4.14-1) bullseye: resolved (fixed in 1.4.14-1) forky: resolved (fixed in 1.4.14-1) sid: resolved (fixed in 1.4.14-1) trixie: resolved (fixed in 1.4.14-1)
debian
Debian Mosquitto vulnerabilities | cvebase