356
VMScore

CVE-2019-11779

Published: 19/09/2019 Updated: 07/11/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

It exists that Mosquitto incorrectly handled certain specially crafted input and network packets. A remote attacker could use this to cause a denial of service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

eclipse mosquitto

canonical ubuntu linux 19.04

opensuse leap 15.1

opensuse backports sle 15.0

fedoraproject fedora 29

fedoraproject fedora 30

fedoraproject fedora 31

debian debian linux 8.0

debian debian linux 10.0

Vendor Advisories

Mosquitto could be made to crash or run programs if it received specially crafted network traffic ...
Debian Bug report logs - #940654 mosquitto: CVE-2019-11779: Excess hierarchy characters on subscribe causes crash Package: mosquitto; Maintainer for mosquitto is Roger A Light <roger@atchooorg>; Source for mosquitto is src:mosquitto (PTS, buildd, popcon) Reported by: Roger Light <roger@atchooorg> Date: Wed, 18 Sep ...
A vulnerability was discovered in mosquitto, a MQTT version 31/311 compatible message broker, allowing a malicious MQTT client to cause a denial of service (stack overflow and daemon crash), by sending a specially crafted SUBSCRIBE packet containing a topic with a extremely deep hierarchy For the stable distribution (buster), this problem has b ...