--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2018-aa66b877bb
2018-10-31 13:56:49.107549
--------------------------------------------------------------------------------

Name        : mosquitto
Product     : Fedora EPEL 7
Version     : 1.5.3
Release     : 1.el7
URL         : http://mosquitto.org/
Summary     : An Open Source MQTT v3.1/v3.1.1 Broker
Description :
Mosquitto is an open source message broker that implements the MQ Telemetry
Transport protocol version 3.1 and 3.1.1 MQTT provides a lightweight method
of carrying out messaging using a publish/subscribe model. This makes it
suitable for "machine to machine" messaging such as with low power sensors
or mobile devices such as phones, embedded computers or micro-controllers
like the Arduino.

--------------------------------------------------------------------------------
Update Information:

Release 1.5.3  Security:  * Fix CVE-2018-12543. If a message is sent to
Mosquitto with a topic that begins with $, but is not $SYS, then an assert that
should be unreachable is triggered and Mosquitto will exit.  Broker:  * Elevate
log level to warning for situation when socket limit is hit. * Remove
requirement to use `user root` in snap package config files. * Fix retained
messages not sent by bridges on outgoing topics at the first connection. *
Documentation fixes. * Fix duplicate clients being added to by_id hash before
the old client was removed. * Fix Windows version not starting if include_dir
did not contain any files.  Build:  * Various fixes to ease building.  Further
details here:  http://mosquitto.org/ChangeLog.txt
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1588904 - CVE-2017-7654 mosquitto: Memory leak allows 
unauthenticated clients to send crafted CONNECT packets causing a denial of 
service [epel-7]
        https://bugzilla.redhat.com/show_bug.cgi?id=1588904
  [ 2 ] Bug #1588901 - CVE-2017-7653 mosquitto: Improper handling of UTF-8 
strings allows malicious clients to cause other clients to disconnect [epel-7]
        https://bugzilla.redhat.com/show_bug.cgi?id=1588901
--------------------------------------------------------------------------------

This update can be installed with the "yum" update programs.  Use
su -c 'yum update mosquitto' at the command line.
For more information, refer to "YUM", available at
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7\
/html/System_Administrators_Guide/ch-yum.html

All packages are signed with the Fedora EPEL GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
epel-package-announce mailing list -- 
[email protected]
To unsubscribe send an email to 
[email protected]
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]

Reply via email to