APP: Eclipse Mosquitto CVE-2018-12543 Denial of Service

This signature detects attempts to exploit a known vulnerability against Eclipse Mosquitto versions 1.5 to 1.5.2 . A successful attack can result in a denial-of-service condition.

Extended Description

In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, e.g. $test/test, then an assert is triggered that should otherwise not be reachable and Mosquitto will exit.

Affected Products

Eclipse mosquitto

References

CVE: CVE-2018-12543

Short Name
APP:MISC:MQTT-TOPIC-ECLIPSE
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
CVE-2018-12543 Denial Eclipse Mosquitto Service of
Release Date
03/12/2019
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Eclipse

CVSS Score

5.0

Found a potential security threat?