Skip to content

Commit

Permalink
Update CVE information.
Browse files Browse the repository at this point in the history
  • Loading branch information
ralight committed Apr 10, 2021
1 parent 3452291 commit d5ecd9f
Show file tree
Hide file tree
Showing 3 changed files with 6 additions and 5 deletions.
5 changes: 2 additions & 3 deletions ChangeLog.txt
Expand Up @@ -2,10 +2,9 @@
==================

Security:
- CVE-xxxx-xxxx: If an authenticated client connected with MQTT v5 sent a
- CVE-2021-23980: If an authenticated client connected with MQTT v5 sent a
malformed CONNACK message to the broker a NULL pointer dereference occurred,
most likely resulting in a segfault. This will be updated with the CVE
number when it is assigned.
most likely resulting in a segfault.
Affects versions 2.0.0 to 2.0.9 inclusive.

Broker:
Expand Down
3 changes: 2 additions & 1 deletion www/pages/security.md
Expand Up @@ -19,7 +19,7 @@ follow the steps on [Eclipse Security] page to report it.
Listed with most recent first. Further information on security related issues
can be found in the [security category].

* April 2021: CVE-xxxx-xxxx Affecting versions **2.0.0** to **2.0.9**
* April 2021: [CVE-2021-28166] Affecting versions **2.0.0** to **2.0.9**
inclusive, fixed in **2.0.10**.
* December 2020: Running mosquitto_passwd with the following arguments only
`mosquitto_passwd -b password_file username password` would cause the
Expand Down Expand Up @@ -69,6 +69,7 @@ can be found in the [security category].
[Eclipse Security]: https://www.eclipse.org/security/
[security category]: /blog/categories/security/

[CVE-2021-28166]: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28166
[CVE-2019-11779]: https://nvd.nist.gov/vuln/detail/CVE-2019-11779
[CVE-2019-11778]: https://nvd.nist.gov/vuln/detail/CVE-2019-11778
[CVE-2018-20145]: https://nvd.nist.gov/vuln/detail/CVE-2018-20145
Expand Down
3 changes: 2 additions & 1 deletion www/posts/2021/04/version-2-0-10-released.md
Expand Up @@ -13,7 +13,7 @@ Versions 2.0.10 of Mosquitto has been released. This is a security and bugfix
release.

# Security
- CVE-xxxx-xxxx: If an authenticated client connected with MQTT v5 sent a
- [CVE-2021-23980]: If an authenticated client connected with MQTT v5 sent a
malformed CONNACK message to the broker a NULL pointer dereference occurred,
most likely resulting in a segfault. This will be updated with the CVE
number when it is assigned.
Expand Down Expand Up @@ -41,6 +41,7 @@ release.
- Fix CMake cross compile builds not finding opensslconf.h. Closes [#2160].
- Fix build on Solaris non-sparc. Closes [#2136].

[CVE-2021-23980]: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28166
[#2134]: https://github.com/eclipse/mosquitto/issues/2134
[#2136]: https://github.com/eclipse/mosquitto/issues/2136
[#2152]: https://github.com/eclipse/mosquitto/issues/2152
Expand Down

0 comments on commit d5ecd9f

Please sign in to comment.