Stack Overflow Vulnerability in Eclipse Mosquitto MQTT Broker
CVE-2019-11779
6.5MEDIUM
Key Information:
- Vendor
The Eclipse Foundation
- Status
- Vendor
- CVE Published:
- 19 September 2019
What is CVE-2019-11779?
In versions 1.5.0 to 1.6.5 of Eclipse Mosquitto, a stack overflow can occur if a malicious MQTT client sends a SUBSCRIBE packet featuring an excessively long topic consisting of around 65400 or more '/' characters. This improper input handling can lead to unexpected behavior in the MQTT broker, potentially allowing an attacker to disrupt service or exploit additional vulnerabilities.
Affected Version(s)
Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive