CVE-2019-11779: Medium severity Eclipse Mosquitto vulnerability
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11779?
CVE-2019-11779 is a vulnerability in Eclipse Mosquitto 1.5.0 to 1.6.5 that can cause a stack overflow when a malicious MQTT client sends a SUBSCRIBE packet with a topic containing a large number of '/' characters.
How does CVE-2019-11779 affect Eclipse Mosquitto?
CVE-2019-11779 affects Eclipse Mosquitto versions 1.5.0 to 1.6.5, inclusive.
What is the severity level of CVE-2019-11779?
CVE-2019-11779 has a severity level of high with a score of 6.5.
How can I fix CVE-2019-11779?
To fix CVE-2019-11779, update your Eclipse Mosquitto installation to version 1.5.7-1+deb10u1 or higher, or version 1.6.6-1 or higher, depending on the package and source you are using.
Where can I find more information about CVE-2019-11779?
You can find more information about CVE-2019-11779 on the MITRE CVE database, Eclipse Bugzilla, and the Ubuntu Security Notices.