Package "libmosquitto1"

Name: libmosquitto1


MQTT version 3.1/3.1.1 client library

Latest version: 1.4.8-1ubuntu0.16.04.6
Release: xenial (16.04)
Level: updates
Repository: universe
Head package: mosquitto
Homepage: http://mosquitto.org/


Save this URL for the latest version of "libmosquitto1": https://www.ubuntuupdates.org/libmosquitto1

Download "libmosquitto1"

Other versions of "libmosquitto1" in Xenial

Repository Area Version
base universe 1.4.8-1build1
security universe 1.4.8-1ubuntu0.16.04.6


Version: 1.4.8-1ubuntu0.16.04.1 2017-05-31 10:06:39 UTC

  mosquitto (1.4.8-1ubuntu0.16.04.1) xenial-security; urgency=low

  * SECURITY UPDATE: Pattern ACL can be bypassed by using a username/client id
    set to '+' or '#' (LP: #1692818).
    - debian/patches/mosquitto-1.4.8_cve-2017-7650.patch: Reject send/receive
      of messages to/from clients with a '+', '#' or '/' in their
      username/client id.
    - CVE-2017-7650

 -- <email address hidden> (Roger A. Light) Tue, 23 May 2017 22:14:40 +0100

1692818 Mosquitto pattern ACLs can be circumvented with special client ids or usernames

About   -   Send Feedback to @ubuntu_updates