Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 4388-1] mosquitto security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 4388-1] mosquitto security update


Chronologisch Thread 
  • From: Moritz Muehlenhoff <jmm AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 4388-1] mosquitto security update
  • Date: Sun, 10 Feb 2019 19:00:34 +0000
  • List-archive: https://lists.debian.org/msgid-search/20190210190034.h42ghj4ptc3y3ne3 AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-return-path: <jmm AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Sun, 10 Feb 2019 19:00:49 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <ai68iXjrfvC.A.sRH.hTHYcB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4388-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
February 10, 2019 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : mosquitto
CVE ID : CVE-2018-12546 CVE-2018-12550 CVE-2018-12551

Three vulnerabilities were discovered in the Mosquitto MQTT broker, which
could result in authentication bypass. Please refer to
https://mosquitto.org/blog/2019/02/version-1-5-6-released/ for additional
information.

For the stable distribution (stretch), these problems have been fixed in
version 1.4.10-3+deb9u3.

We recommend that you upgrade your mosquitto packages.

For the detailed security status of mosquitto please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/mosquitto

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlxgdIAACgkQEMKTtsN8
Tjai+g/+Lct38ZTjmWx/BWTemuWpC9AYL3A+raa584xhjd3HdIUKeaYOsjwRsZJV
7yitjjS8TRd1LAVBd/nI7Sj3XLzqdq5jf1ESOmR1q1UT0WlfvVfNePqLRJ9wt5Yi
TMQySjXyz+OOK5at4GH4musFScJKbjR07LA9jWlbJpAgjuhn9sXHtyWCf3t85qtA
CwQL8SbtB5kONI5QGhy0nIHq6nMUMVq052fWwj7WqCpsnl24yhRD3GeYQhgqqnU3
EBp/V5ngaXKLC7rYcDezmO7wXV6A8YH2LNhbcM6NWrOGEKR0OOy1C+7PWcKjj97A
vCU+i8ylL2DjZPnd4GUjKBfEIcUtWirKwLreEru40mfWRRvd9el1WMLuIgG+FEea
MJvDD9VTtmRjQ9ErXc6OiiTG6PWjtLmRSrJhvwPiyU4vDQ58VVD2z64TXUyhKb9z
zGBRauvf1B7wya++R+uz00MdcQx1irysJwSBbuPUGWP2LydOcnyswbOVajC4VXco
Fq1VHnYEjnEbEWd9JpDTz5sM+g3DorGL5CslgFnPwjTL/vR0mQ2fR/fFHyt8nnuT
SrF6K8yJ/9IeXWuCoWw4QWIqWvKwCZcB+Tn0ZSjWdXeqCiynG+OjpYvnI6v7lWmz
QMmUM8yip2//mk249LMS+UoE2mhzEfLYoXWUmeEL64OW0mnn/4w=
=AlaR
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 4388-1] mosquitto security update, Moritz Muehlenhoff, 10.02.2019

Archiv bereitgestellt durch MHonArc 2.6.19.

Seitenanfang