security advisorymoderateDebian
The following vulnerabilities have been discovered in the package mosquitto, MQTT message broker. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4059-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Abhijith PA February 20, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : mosquitto Version : 2.0.11-1+deb11u2 CVE ID : CVE-2024-3935 CVE-2024-10525 The following vulnerabilities have been discovered in the package mosquitto, MQTT message broker. CVE-2024-3935 If a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming topic configured that makes use of topic remapping, then if the remote connection sends a crafted PUBLISH packet to the broker a double free will occur with a subsequent crash of the broker. CVE-2024-10525 If a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients. For Debian 11 bullseye, these problems have been fixed in version 2.0.11-1+deb11u2. We recommend that you upgrade your mosquitto packages. For the detailed security status of mosquitto please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/mosquitto Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-4898-1 addresses vulnerabilities in the OpenSSL library. It is advised to update your system.. Debian Mosquitto Security, MQTT Broker Security, Mosquitto Crash Fix. . LinuxSecurity.com Team
Feb 20, 2025
Debian LTS