mosquitto/mosquitto-2.0.12.tar.gz.sig
Martin Hauke 9cc75b7829 Accepting request 917167 from home:mnhauke
- Update to version 2.0.12
  * Includes security fixes for
    CVE-2021-34434 (bsc#1190048) and CVE-2020-13849 (bsc#1190101)
  Security :
  * An MQTT v5 client connecting with a large number of
    user-property properties could cause excessive CPU usage,
    leading to a loss of performance and possible denial of
    service. This has been fixed.
  * Fix `max_keepalive` not applying to MQTT v3.1.1 and v3.1
    connections.  These clients are now rejected if their keepalive
    value exceeds max_keepalive. This option allows CVE-2020-13849,
    which is for the MQTT v3.1.1 protocol itself rather than an
    implementation, to be addressed.
  * Using certain listener related configuration options e.g.
    `cafile`, that apply to the default listener without defining
    any listener would cause a remotely accessible listener to be
    opened that was not confined to the local machine but did have
    anonymous access enabled, contrary to the documentation.
    This has been fixed. Closes #2283.
  * CVE-2021-34434: If a plugin had granted ACL subscription access
    to a durable/non-clean-session client, then removed that
    access,the client would keep its existing subscription. This
    has been fixed.
  * Incoming QoS 2 messages that had not completed the QoS flow
    were not being checked for ACL access when a clean
    session=False client was reconnecting.  This has been fixed.
  Broker:
  * Fix possible out of bounds memory reads when reading a
    corrupt/crafted configuration file. Unless your configuration
    file is writable by untrusted users this is not a risk.

OBS-URL: https://build.opensuse.org/request/show/917167
OBS-URL: https://build.opensuse.org/package/show/network:messaging:mqtt/mosquitto?expand=0&rev=58
2021-10-12 18:56:06 +00:00

17 lines
833 B
Standard ML

-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEEoNbuodyuSaY1o7Lwd5si37PnF7cFAmEulDIACgkQd5si37Pn
F7cJvA//UNSoMaisrPFdGpwG0vsaqJhWIXfAYvq9ICBcc0Sf7TqJ17CJ2Gz/89ii
qy0av5FIE/+t4K4i8KAlHFNVvHdCf4Qgod+yeplXNR0szYdziC75fDhOzoV88oyj
QF0Qq+652FZxAqSx+V7PdW3nYRW58TjPXE+DlKPG9hk0vMEPZYxiMAJE6jdlLxKP
1X7UI0q+R+R+z5/nKtoF++G8rOfHWvunGMsPBPVVKHvLWHyCgA/t+ajbMtThPt9t
raRV47lzUaZ582soPv5pn4qyBd3+4+mhvd5gdZe/DRWFluht73SjU/M5VkgeO23y
RhR9KZWzlYpH1LZg9ujpM3Cv1kLYDbr8RIRUYKPfgd5PbZ3KIzEl2lkAm9bZFw2j
LmfzXEToNWy70zwvoCiA2OMZi3uBMSrhk9NMIoKIFISCaX6eqPy0xOF49asIe7SK
WlI3VDrgKGU+YGcfnacNhaqiUURkmp4v0tEKrNBvm7c6tR+jRQ23C3YR4BJWkA+W
vHdsFfFi8tzUeA6xhuZRXCC5wy9LfHvLQarJWKZjjM0vAWz7cx0kIS3W3klJT880
vjD3IwyQh2ktjSAml5XFVkxVun1/tF92eWS/s3c2fOE7Jv9hDVKPIQmvFXN3k9CY
LzSW+Bg7bTcCD6KLtygmiR3666atkQ13ugIdLFrvCHu3l/4d5d0=
=PNLS
-----END PGP SIGNATURE-----