CVE-2018-12546

NameCVE-2018-12546
DescriptionIn Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoked, the retained message will still be published to clients that subscribe to that topic in the future. In some applications this may result in clients being able cause effects that would otherwise not be allowed.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-4388-1
Debian Bugs921976

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mosquitto (PTS)jessie, jessie (lts)1.3.4-2+deb8u4vulnerable
stretch (security), stretch (lts), stretch1.4.10-3+deb9u5fixed
buster (security), buster, buster (lts)1.5.7-1+deb10u1fixed
bullseye (security), bullseye2.0.11-1+deb11u1fixed
bookworm (security), bookworm2.0.11-1.2+deb12u1fixed
sid, trixie2.0.20-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mosquittosourcewheezy(unfixed)end-of-life
mosquittosourcestretch1.4.10-3+deb9u3DSA-4388-1
mosquittosource(unstable)1.5.6-1921976

Notes

[jessie] - mosquitto <ignored> (Minor issue)
https://mosquitto.org/blog/2019/02/version-1-5-6-released/
https://mosquitto.org/files/cve/2018-12546

Search for package or bug name: Reporting problems