{"id":"MGASA-2021-0349","summary":"Updated mosquitto packages fix security vulnerability","details":"Updated mosquitto packages fix security vulnerability:\n\nIf an authenticated client connected with MQTT v5 sent a crafted CONNECT\nmessage to the broker a memory leak would occur.\n\nFor other fixes in this update, see the mosquitto.org blog reference.\n","modified":"2026-04-16T04:24:44.860873Z","published":"2021-07-12T21:57:00Z","references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2021-0349.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=29024"},{"type":"WEB","url":"http://mosquitto.org/blog/2021/06/version-2-0-11-released/"}],"affected":[{"package":{"name":"mosquitto","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/mosquitto?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.15-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0349.json"}},{"package":{"name":"uthash","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/uthash?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.0-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0349.json"}},{"package":{"name":"mosquitto","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/mosquitto?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.11-1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0349.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}