Debian Security Advisory

DSA-4570-1 mosquitto -- security update

Date Reported:
17 Nov 2019
Affected Packages:
Security database references:
In the Debian bugtracking system: Bug 940654.
In Mitre's CVE dictionary: CVE-2019-11779.
More information:

A vulnerability was discovered in mosquitto, a MQTT version 3.1/3.1.1 compatible message broker, allowing a malicious MQTT client to cause a denial of service (stack overflow and daemon crash), by sending a specially crafted SUBSCRIBE packet containing a topic with a extremely deep hierarchy.

For the stable distribution (buster), this problem has been fixed in version 1.5.7-1+deb10u1.

We recommend that you upgrade your mosquitto packages.

For the detailed security status of mosquitto please refer to its security tracker page at: