USN-6685-1: mqtt-client vulnerability
It was discovered that mqtt-client incorrectly handled memory while parsing malformed MQTT frames. An attacker could possibly use this issue to cause a crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6685-1?
The severity of USN-6685-1 is classified as high due to the potential for denial of service or arbitrary code execution.
How do I fix USN-6685-1?
To fix USN-6685-1, upgrade the libmqtt-client-java package to the latest version specified in the advisory for your Ubuntu version.
What causes vulnerability USN-6685-1?
USN-6685-1 is caused by incorrect memory handling in the mqtt-client while parsing malformed MQTT frames.
Which versions of Ubuntu are affected by USN-6685-1?
USN-6685-1 affects Ubuntu 20.04, 18.04, and 16.04 with specific versions of the libmqtt-client-java package.
What are the potential impacts of USN-6685-1?
The potential impacts of USN-6685-1 include crashing the application or allowing an attacker to execute arbitrary code.