CVE-2019-11779 describes a stack overflow vulnerability in Eclipse Mosquitto versions 1.5.0 to 1.6.5. A malicious MQTT client can trigger this by sending a SUBSCRIBE packet with an excessively long topic string containing approximately 65400 or more '/' characters. This vulnerability affects various distributions including Canonical, Debian, Eclipse, FedoraProject, and openSUSE. The vulnerability has a CVSS score of 6.5 (Medium), indicating it can be exploited remotely with low attack complexity and requires low privileges, leading to high availability impact (denial of service). There is no confidentiality or integrity impact. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.5, < 1.5.9CPE matchmatch criteria | cpe:2.3:a:eclipse:mosquitto:*:*:*:*:*:*:*:* | ||
>= 1.6, < 1.6.6CPE matchmatch criteria | cpe:2.3:a:eclipse:mosquitto:*:*:*:*:*:*:*:* | ||
19.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.