APP: Eclipse Mosquitto MQTT SUBSCRIBE Topic Stack Overflow
This signature detects attempts to exploit a known vulnerability against Eclipse Mosquitto. A successful attack can result in a denial-of-service condition.
Extended Description
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.
Affected Products
Fedoraproject fedora
References
CVE: CVE-2019-11779
srx-branch-19.3
vsrx3bsd-19.2
srx-19.4
vsrx3bsd-19.4
srx-branch-19.4
vsrx-19.4
vsrx-19.2
srx-19.3
srx-branch-12.3
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx-12.3
vmx-19.3
srx-12.3
Opensuse
Fedoraproject
Eclipse
Debian
Canonical
4.0