VulnerabilityModified
CVE-2019-11779
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.
MEDIUM 6.5EPSS 2.74%
Does this matter?
Lower severity and a low EPSS score (2.74%). Track it; it rarely justifies an emergency change on its own.
Description
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.74% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-754, CWE-674
- Affected
- eclipse/mosquitto · canonical/ubuntu linux · opensuse/backports sle · opensuse/leap · fedoraproject/fedora · debian/debian linux
- Source
- emo@eclipse.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00077.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00008.htmlMailing List, Third Party Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=551160Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00035.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D4WMHIM64Q35NGTR6R3ILZUL4MA4ANB5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HFWQBNFTAVHPUYNGYO2TCPF5PCSWC2Z7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWNVTFA2CKXERXRYPYE2YFTZP4GNBGYY/
- https://seclists.org/bugtraq/2019/Nov/25Mailing List, Third Party Advisory
- https://usn.ubuntu.com/4137-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4570Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00077.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00008.htmlMailing List, Third Party Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=551160Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00035.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D4WMHIM64Q35NGTR6R3ILZUL4MA4ANB5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HFWQBNFTAVHPUYNGYO2TCPF5PCSWC2Z7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWNVTFA2CKXERXRYPYE2YFTZP4GNBGYY/
- https://seclists.org/bugtraq/2019/Nov/25Mailing List, Third Party Advisory
- https://usn.ubuntu.com/4137-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4570Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.