Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 442
Alerts This Week
Warning Icon 1 442

Mageia 8: 2021-0445 Critical: Mosquitto Subscription Issue Fix

mageia
Calendar Grey September 29, 2021
Scroller Mageia
Mosquitto revisions address urgent vulnerabilities impacting earlier iterations. Uncover recent updates and guidance.
Mosquitto is updated to 2.0.12 to fix security vulnerability: In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to m...

Summary

Mosquitto is updated to 2.0.12 to fix security vulnerability:
In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked (CVE-2021-34434).

References

- https://bugs.mageia.org/show_bug.cgi?id=29454

- https://mosquitto.org/blog/2021/08/version-2-0-12-released/

- https://www.cve.org/CVERecord?id=CVE-2021-34434

Resolution

SRPMS

- 8/core/mosquitto-2.0.12-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 29 Sep 2021
URL: https://advisories.mageia.org/MGASA-2021-0445.html
Type: security
CVE: CVE-2021-34434

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.