• [SECURITY] [DSA 4388-1] mosquitto security update

    From Moritz Muehlenhoff@1:229/2 to All on Sun Feb 10 20:10:02 2019
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4388-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff February 10, 2019 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : mosquitto
    CVE ID : CVE-2018-12546 CVE-2018-12550 CVE-2018-12551

    Three vulnerabilities were discovered in the Mosquitto MQTT broker, which
    could result in authentication bypass. Please refer to https://mosquitto.org/blog/2019/02/version-1-5-6-released/ for additional information.

    For the stable distribution (stretch), these problems have been fixed in version 1.4.10-3+deb9u3.

    We recommend that you upgrade your mosquitto packages.

    For the detailed security status of mosquitto please refer to
    its security tracker page at: https://security-tracker.debian.org/tracker/mosquitto

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlxgdIAACgkQEMKTtsN8 Tjai+g/+Lct38ZTjmWx/BWTemuWpC9AYL3A+raa584xhjd3HdIUKeaYOsjwRsZJV 7yitjjS8TRd1LAVBd/nI7Sj3XLzqdq5jf1ESOmR1q1UT0WlfvVfNePqLRJ9wt5Yi TMQySjXyz+OOK5at4GH4musFScJKbjR07LA9jWlbJpAgjuhn9sXHtyWCf3t85qtA CwQL8SbtB5kONI5QGhy0nIHq6nMUMVq052fWwj7WqCpsnl24yhRD3GeYQhgqqnU3 EBp/V5ngaXKLC7rYcDezmO7wXV6A8YH2LNhbcM6NWrOGEKR0OOy1C+7PWcKjj97A vCU+i8ylL2DjZPnd4GUjKBfEIcUtWirKwLreEru40mfWRRvd9el1WMLuIgG+FEea MJvDD9VTtmRjQ9ErXc6OiiTG6PWjtLmRSrJhvwPiyU4vDQ58VVD2z64TXUyhKb9z zGBRauvf1B7wya++R+uz00MdcQx1irysJwSBbuPUGWP2LydOcnyswbOVajC4VXco Fq1VHnYEjnEbEWd9JpDTz5sM+g3DorGL5CslgFnPwjTL/vR0mQ2fR/fFHyt8nnuT SrF6K8yJ/9IeXWuCoWw4QWIqWvKwCZcB+Tn0ZSjWdXeqCiynG+OjpYvnI6v7lWmz QMmUM8yip2//mk249LMS+UoE2mhzEfLYoXWUmeEL64OW0mnn/4w=
    =AlaR
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)