mosquitto: CVE-2017-9868: mosquitto.db can be read by all

Related Vulnerabilities: CVE-2017-9868  

Debian Bug report logs - #865959
mosquitto: CVE-2017-9868: mosquitto.db can be read by all

version graph

Reported by: Salvatore Bonaccorso <carnil@debian.org>

Date: Mon, 26 Jun 2017 05:39:02 UTC

Severity: important

Tags: fixed-upstream, security, upstream

Found in version mosquitto/1.3.4-2

Fixed in version mosquitto/1.4.14-1

Done: Salvatore Bonaccorso <carnil@debian.org>

Bug is archived. No further changes may be made.

Forwarded to https://github.com/eclipse/mosquitto/issues/468

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Roger A. Light <roger@atchoo.org>:
Bug#865959; Package src:mosquitto. (Mon, 26 Jun 2017 05:39:04 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Roger A. Light <roger@atchoo.org>. (Mon, 26 Jun 2017 05:39:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: mosquitto: CVE-2017-9868: mosquitto.db can be read by all
Date: Mon, 26 Jun 2017 07:35:05 +0200
Source: mosquitto
Version: 1.3.4-2
Severity: important
Tags: security upstream
Forwarded: https://github.com/eclipse/mosquitto/issues/468

Hi,

the following vulnerability was published for mosquitto.

CVE-2017-9868[0]:
| In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is
| world readable, which allows local users to obtain sensitive MQTT topic
| information.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-9868
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9868
[1] https://github.com/eclipse/mosquitto/issues/468

Regards,
Salvatore



Added tag(s) fixed-upstream. Request was from bts-link-upstream@lists.alioth.debian.org to control@bugs.debian.org. (Thu, 29 Jun 2017 17:45:14 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Roger A. Light <roger@atchoo.org>:
Bug#865959; Package src:mosquitto. (Sat, 23 Sep 2017 17:03:03 GMT) (full text, mbox, link).


Acknowledgement sent to Emilio Pozuelo Monfort <pochu@debian.org>:
Extra info received and forwarded to list. Copy sent to Roger A. Light <roger@atchoo.org>. (Sat, 23 Sep 2017 17:03:03 GMT) (full text, mbox, link).


Message #12 received at 865959@bugs.debian.org (full text, mbox, reply):

From: Emilio Pozuelo Monfort <pochu@debian.org>
To: 865959@bugs.debian.org, Salvatore Bonaccorso <carnil@debian.org>
Subject: Re: mosquitto: CVE-2017-9868: mosquitto.db can be read by all
Date: Sat, 23 Sep 2017 18:59:35 +0200
On Mon, 26 Jun 2017 07:35:05 +0200 Salvatore Bonaccorso <carnil@debian.org> wrote:
> Source: mosquitto
> Version: 1.3.4-2
> Severity: important
> Tags: security upstream
> Forwarded: https://github.com/eclipse/mosquitto/issues/468
> 
> Hi,
> 
> the following vulnerability was published for mosquitto.
> 
> CVE-2017-9868[0]:
> | In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is
> | world readable, which allows local users to obtain sensitive MQTT topic
> | information.
> 
> If you fix the vulnerability please also make sure to include the
> CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

This is now fixed upstream:

https://github.com/eclipse/mosquitto/commit/09cb1b61c8f48284d9c42bd911faa7525cc689c7

Cheers,
Emilio



Information forwarded to debian-bugs-dist@lists.debian.org, Roger A. Light <roger@atchoo.org>:
Bug#865959; Package src:mosquitto. (Sat, 28 Oct 2017 12:18:03 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
Extra info received and forwarded to list. Copy sent to Roger A. Light <roger@atchoo.org>. (Sat, 28 Oct 2017 12:18:03 GMT) (full text, mbox, link).


Message #17 received at 865959@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: 865959@bugs.debian.org
Subject: Re: Bug#865959: mosquitto: CVE-2017-9868: mosquitto.db can be read by all
Date: Sat, 28 Oct 2017 14:14:29 +0200
Hi

On Mon, Jun 26, 2017 at 07:35:05AM +0200, Salvatore Bonaccorso wrote:
> Source: mosquitto
> Version: 1.3.4-2
> Severity: important
> Tags: security upstream
> Forwarded: https://github.com/eclipse/mosquitto/issues/468
> 
> Hi,
> 
> the following vulnerability was published for mosquitto.
> 
> CVE-2017-9868[0]:
> | In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is
> | world readable, which allows local users to obtain sensitive MQTT topic
> | information.

Any news for the fix to unstable?

Regards,
Salvatore



Marked as fixed in versions mosquitto/1.4.14-1. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sun, 24 Dec 2017 13:39:04 GMT) (full text, mbox, link).


Marked Bug as done Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sun, 24 Dec 2017 13:39:06 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Sun, 24 Dec 2017 13:39:07 GMT) (full text, mbox, link).


Message sent on to Salvatore Bonaccorso <carnil@debian.org>:
Bug#865959. (Sun, 24 Dec 2017 13:39:10 GMT) (full text, mbox, link).


Message #26 received at 865959-submitter@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: control@bugs.debian.org
Cc: 865959-submitter@bugs.debian.org
Subject: closing 865959
Date: Sun, 24 Dec 2017 14:37:54 +0100
close 865959 1.4.14-1
thanks




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Mon, 29 Jan 2018 07:27:57 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 14:35:40 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.