[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2019-11779Date: (C)2019-09-23   (M)2023-12-22


In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 6.5CVSS Score : 4.0
Exploit Score: 2.8Exploit Score: 8.0
Impact Score: 3.6Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: LOWAuthentication: SINGLE
User Interaction: NONEConfidentiality: NONE
Scope: UNCHANGEDIntegrity: NONE
Confidentiality: NONEAvailability: PARTIAL
Integrity: NONE 
Availability: HIGH 
  
Reference:
https://seclists.org/bugtraq/2019/Nov/25
DSA-4570
FEDORA-2019-4c69fb4cd7
FEDORA-2019-8b83c261dd
FEDORA-2019-d99e2329cb
USN-4137-1
https://lists.debian.org/debian-lts-announce/2019/10/msg00035.html
https://bugs.eclipse.org/bugs/show_bug.cgi?id=551160
openSUSE-SU-2019:2206
openSUSE-SU-2019:2247

CPE    1
cpe:/o:debian:debian_linux:8.0
CWE    1
CWE-674
OVAL    6
oval:org.secpod.oval:def:117170
oval:org.secpod.oval:def:117171
oval:org.secpod.oval:def:1801636
oval:org.secpod.oval:def:705183
...

© SecPod Technologies