SB2019021002 - Permissions, Privileges, and Access Controls in mosquitto (Alpine package)
Published: February 10, 2019
Security Bulletin ID
SB2019021002
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2018-12550)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to insecure default permissions to topics and messages, if the ACL file is blank. A remote attacker can gain unauthorized access to sensitive information.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=68e4e4a13ae7d52d37708f6d7393a5a6ef0ef856
- https://git.alpinelinux.org/aports/commit/?id=1a43a53ec67e2c5ca5fa770026cd904d745f32a1
- https://git.alpinelinux.org/aports/commit/?id=cdf3e55bbad03e4036a926c6ec33aae93e695537
- https://git.alpinelinux.org/aports/commit/?id=231048d9b3314a33f93647991dc803fdf5cc7ff7
- https://git.alpinelinux.org/aports/commit/?id=0615c8c70a2ec6b20460291a2755e9e36f393205
- https://git.alpinelinux.org/aports/commit/?id=c000685cbe12c9f51e9d651aff660e8b3ebc8f70