Debian Security Advisory

DSA-4325-1 mosquitto -- security update

Date Reported:
25 Oct 2018
Affected Packages:
Security database references:
In the Debian bugtracking system: Bug 911265, Bug 911266.
In Mitre's CVE dictionary: CVE-2017-7651, CVE-2017-7652, CVE-2017-7653, CVE-2017-7654.
More information:

It was discovered that mosquitto, an MQTT broker, was vulnerable to remote denial-of-service attacks that could be mounted using various vectors.

For the stable distribution (stretch), these problems have been fixed in version 1.4.10-3+deb9u2.

We recommend that you upgrade your mosquitto packages.

For the detailed security status of mosquitto please refer to its security tracker page at: