Candidate: CVE-2019-5432 PublicDate: 2019-05-06 17:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5432 https://hackerone.com/reports/541354 Description: A specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions < 3.5.1, 4.0.0 - 4.1.3, 5.0.0 - 5.6.1, 6.0.0 - 6.1.2 for decoding. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=928673 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_node-mqtt-packet: upstream_node-mqtt-packet: released (6.0.0-2) precise/esm_node-mqtt-packet: DNE trusty/esm_node-mqtt-packet: DNE xenial_node-mqtt-packet: DNE bionic_node-mqtt-packet: needed cosmic_node-mqtt-packet: ignored (reached end-of-life) disco_node-mqtt-packet: ignored (reached end-of-life) eoan_node-mqtt-packet: not-affected (6.0.0-2) focal_node-mqtt-packet: not-affected (6.0.0-2) groovy_node-mqtt-packet: not-affected (6.0.0-2) hirsute_node-mqtt-packet: not-affected (6.0.0-2) impish_node-mqtt-packet: not-affected (6.0.0-2) jammy_node-mqtt-packet: not-affected (6.0.0-2) devel_node-mqtt-packet: not-affected (6.0.0-2)