Medium severity6.5NVD Advisory· Published Sep 19, 2019· Updated Jun 17, 2026
CVE-2019-11779
CVE-2019-11779
Description
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13- cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- osv-coords2 versionspkg:rpm/opensuse/mosquitto&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/mosquitto&distro=SUSE%20Package%20Hub%2015%20SP1
< 1.5.7-lp151.2.3.1+ 1 more
- (no CPE)range: < 1.5.7-lp151.2.3.1
- (no CPE)range: < 1.5.7-bp151.3.3.1
Patches
Vulnerability mechanics
References
10- lists.opensuse.org/opensuse-security-announce/2019-09/msg00077.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-10/msg00008.htmlnvdMailing ListThird Party Advisory
- bugs.eclipse.org/bugs/show_bug.cginvdVendor Advisory
- lists.debian.org/debian-lts-announce/2019/10/msg00035.htmlnvdMailing ListThird Party Advisory
- seclists.org/bugtraq/2019/Nov/25nvdMailing ListThird Party Advisory
- usn.ubuntu.com/4137-1/nvdThird Party Advisory
- www.debian.org/security/2019/dsa-4570nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D4WMHIM64Q35NGTR6R3ILZUL4MA4ANB5/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HFWQBNFTAVHPUYNGYO2TCPF5PCSWC2Z7/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWNVTFA2CKXERXRYPYE2YFTZP4GNBGYY/nvd
News mentions
0No linked articles in our index yet.