CVE-2017-9868: Infoleak
Published Jun 25, 2017
·Updated
In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.
Affected Software
2 affected components
Eclipse Mosquitto<=1.4.12
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Jun 25, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9868?
CVE-2017-9868 has a medium severity level as it allows local users to access sensitive data.
2
How do I fix CVE-2017-9868?
To fix CVE-2017-9868, ensure that the mosquitto.db file has the proper permissions to restrict access.
3
What is affected by CVE-2017-9868?
CVE-2017-9868 affects Eclipse Mosquitto versions up to 1.4.12 and Debian GNU/Linux 8.0.
4
What type of data can be exposed due to CVE-2017-9868?
CVE-2017-9868 can expose sensitive MQTT topic information stored in the mosquitto.db persistence file.
5
Who is primarily impacted by CVE-2017-9868?
Local users on systems running vulnerable versions of Eclipse Mosquitto and Debian GNU/Linux are primarily impacted by CVE-2017-9868.