Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 8: 2021-0445 Critical: Mosquitto Subscription Issue Fix

mageia
Calendar Grey September 29, 2021
Dist Mageia Esm H88
Mosquitto revisions address urgent vulnerabilities impacting earlier iterations. Uncover recent updates and guidance.
Mosquitto is updated to 2.0.12 to fix security vulnerability: In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to m...

Summary

Mosquitto is updated to 2.0.12 to fix security vulnerability:
In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked (CVE-2021-34434).

References

- https://bugs.mageia.org/show_bug.cgi?id=29454

- https://mosquitto.org/blog/2021/08/version-2-0-12-released/

- https://www.cve.org/CVERecord?id=CVE-2021-34434

Resolution

SRPMS

- 8/core/mosquitto-2.0.12-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 29 Sep 2021
URL: https://advisories.mageia.org/MGASA-2021-0445.html
Type: security
CVE: CVE-2021-34434

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here