Bug 13276

Summary: [CVE 21] mosquitto 1.6.12 CVEs found
Product: [ROSA-based products] ROSA Fresh Reporter: Yury <y.tumanov>
Component: System (kernel, glibc, systemd, bash, PAM...)Assignee: ROSA Linux Bugs <bugs>
Status: VERIFIED FIXED QA Contact: ROSA Linux Bugs <bugs>
Severity: critical    
Priority: High CC: a.proklov, m.novosyolov, pastordidi, s.matveev, v.potapov, y.tumanov
Version: AllFlags: v.potapov: qa_verified+
y.tumanov: secteam_verified+
a.proklov: published+
Target Milestone: 2021.1 Fresh R12   
Hardware: All   
OS: Linux   
URL: CVE-2021-34431, CVE-2021-41039,
Whiteboard:
Platform: 2021.1 ROSA Vulnerability identifier:
RPM Package: ISO-related:
Bad POT generating: Upstream:
Attachments: mos1.png

Description Yury 2023-05-03 18:00:45 MSK
Please patch CVEs for package mosquitto version 1.6.12
  
INFO (CVEs are): mosquitto 1.6.12
 cves found
CVE-2021-34431
Desc: In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur, which could be used to provide a DoS attack against the broker.
Link: https://nvd.nist.gov/vuln/detail/CVE-2021-34431
Severity: MEDIUM
CVE-2021-41039
Desc: In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property properties could cause excessive CPU usage, leading to a loss of performance and possible denial of service.
Link: https://nvd.nist.gov/vuln/detail/CVE-2021-41039
Severity: HIGH
Comment 1 Mikhail Novosyolov 2023-05-15 14:29:53 MSK
Не ява, обновить надо, можно поднять версию.
Comment 2 Svyatoslav Matveev 2023-05-22 12:23:55 MSK
********** QA ADVISORY **********

Cve закрыты обновлением.

Проект cjson перенесен из contrib в main,
требуется для сборки mosquitto.

*** cjson

https://abf.io/build_lists/4442859
https://abf.io/build_lists/4442860
https://abf.io/build_lists/4442858
https://abf.io/build_lists/4442862
https://abf.io/build_lists/4442861

*** mosquitto
**  upd: 1.6.12 > 2.0.15

https://abf.io/build_lists/4442866
https://abf.io/build_lists/4442867
https://abf.io/build_lists/4442868
https://abf.io/build_lists/4442869
https://abf.io/build_lists/4442870
Comment 3 Dmitry Postnikov 2023-05-23 12:34:01 MSK
Created attachment 5890 [details]
mos1.png

При установке, почему-то тащит либу lib64mosquitto1 изи Майн, старой версии.
Comment 4 Svyatoslav Matveev 2023-05-23 13:42:04 MSK
(In reply to Dmitry Postnikov from comment #3)
> Created attachment 5890 [details]
> mos1.png
> 
> При установке, почему-то тащит либу lib64mosquitto1 изи Майн, старой версии.

пересобрано ,не должно тащить.

https://abf.io/build_lists/4443281
https://abf.io/build_lists/4443282
https://abf.io/build_lists/4443283
https://abf.io/build_lists/4443284
https://abf.io/build_lists/4443285
Comment 5 Dmitry Postnikov 2023-05-23 21:35:33 MSK
(In reply to Svyatoslav Matveev from comment #4)
> (In reply to Dmitry Postnikov from comment #3)
> > Created attachment 5890 [details]
> > mos1.png
> > 
> > При установке, почему-то тащит либу lib64mosquitto1 изи Майн, старой версии.
> 
> пересобрано ,не должно тащить.
> 
> https://abf.io/build_lists/4443281
> https://abf.io/build_lists/4443282
> https://abf.io/build_lists/4443283
> https://abf.io/build_lists/4443284
> https://abf.io/build_lists/4443285

У контейнеров 404-я страница.
Comment 6 Dmitry Postnikov 2023-05-24 09:59:43 MSK
Контейнеры сами починились, или что-то на абф сделали. Проверяю....
Comment 7 Dmitry Postnikov 2023-05-24 16:02:59 MSK
***************************
The update sent to testings(In reply to Svyatoslav Matveev from comment #2)
> ********** QA ADVISORY **********
> 
> Cve закрыты обновлением.
> 
> Проект cjson перенесен из contrib в main,
> требуется для сборки mosquitto.
> 
> *** cjson
> 
> https://abf.io/build_lists/4442859
> https://abf.io/build_lists/4442860
> https://abf.io/build_lists/4442858
> https://abf.io/build_lists/4442862
> https://abf.io/build_lists/4442861
> 
> *** mosquitto
> **  upd: 1.6.12 > 2.0.15
> > 
> > https://abf.io/build_lists/4443281
> > https://abf.io/build_lists/4443282
> > https://abf.io/build_lists/4443283
> > https://abf.io/build_lists/4443284
> > https://abf.io/build_lists/4443285
> 


***************************
The update sent to testings
Comment 8 Vladimir Potapov 2023-05-30 18:03:43 MSK
cjson-1.7.15-0.gitb45f48.2
https://abf.io/build_lists/4442859
https://abf.io/build_lists/4442860
https://abf.io/build_lists/4442858
https://abf.io/build_lists/4442862
https://abf.io/build_lists/4442861

mosquitto-2.0.15-2
https://abf.io/build_lists/4443281
https://abf.io/build_lists/4443282
https://abf.io/build_lists/4443283
https://abf.io/build_lists/4443284
https://abf.io/build_lists/4443285
********************* Advisory **************************
 upd: 1.6.12 > 2.0.15
*********************************************************
QA Verified
Comment 9 Yury 2023-07-25 14:03:07 MSK
Secteam Verified