SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Eclipse Mosquitto MQTT Buffer Overflow

Category: MISC      

In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.

References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11779


Relevant Information