Fedora 30 : mosquitto (2019-cc896df591)

high Nessus Plugin ID 124786

Language:

Synopsis

The remote Fedora host is missing a security update.

Description

1.6.2 =====

Broker :

- Fix memory access after free, leading to possible crash, when v5 client with Will message disconnects, where the Will message has as its first property one of `content-type`, `correlation-data`, `payload-format-indicator`, or `response-topic`.

- Fix build for WITH_TLS=no.

- Fix Will message not allowing user-property properties.

- Fix broker originated messages (e.g.
$SYS/broker/version) not being published when `check_retain_source` set to true. Closes #1245.

- Fix $SYS/broker/version being incorrectly expired after 60 seconds. Closes #1245.

Library :

- Fix crash after client has been unable to connect to a broker. This occurs when the client is exiting and is part of the final library cleanup routine. Closes #1246.

Clients :

- Fix -L url parsing. Closes #1248.

----

1.6.1 release

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website.
Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected mosquitto package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2019-cc896df591

Plugin Details

Severity: High

ID: 124786

File Name: fedora_2019-cc896df591.nasl

Version: 1.2

Type: local

Agent: unix

Published: 5/13/2019

Updated: 9/23/2019

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:30, p-cpe:/a:fedoraproject:fedora:mosquitto

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 5/11/2019

Vulnerability Publication Date: 5/11/2019

Reference Information