First published: Mon Sep 23 2019(Updated: )
It was discovered that Mosquitto incorrectly handled certain specially crafted input and network packets. A remote attacker could use this to cause a denial of service.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libmosquittopp1 | <1.5.7-1ubuntu0.1 | 1.5.7-1ubuntu0.1 |
=19.04 | ||
All of | ||
ubuntu/mosquitto | <1.5.7-1ubuntu0.1 | 1.5.7-1ubuntu0.1 |
=19.04 | ||
All of | ||
ubuntu/libmosquitto1 | <1.5.7-1ubuntu0.1 | 1.5.7-1ubuntu0.1 |
=19.04 | ||
All of | ||
ubuntu/mosquitto-clients | <1.5.7-1ubuntu0.1 | 1.5.7-1ubuntu0.1 |
=19.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
USN-4137-1
libmosquittopp1, mosquitto, libmosquitto1, mosquitto-clients
By sending specially crafted input and network packets.
Update to version 1.5.7-1ubuntu0.1 of the affected packages.
You can find more information about USN-4137-1 at the following references: [CVE-2019-11779](https://ubuntu.com/security/CVE-2019-11779), [launchpad.net](https://launchpad.net/ubuntu/+source/mosquitto/1.5.7-1ubuntu0.1), [USN-4137-1](https://ubuntu.com/security/notices/USN-4137-1).