]> rtime.felk.cvut.cz Git - coffee/buildroot.git/commit
mosquitto: security bump to version 1.4.15
authorPeter Korsgaard <peter@korsgaard.com>
Wed, 28 Feb 2018 23:11:40 +0000 (00:11 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Tue, 10 Apr 2018 20:06:08 +0000 (22:06 +0200)
commit6758d727502ac73de5f8879f544fc6d9660e5061
treeaa27a5b39dd9c46dd7fcb8578e11b27340b59a98
parent184042f0e5410716f8bc5e26eff72de91624d489
mosquitto: security bump to version 1.4.15

Fixes CVE-2017-7651: Unauthenticated clients can send a crafted CONNECT
packet which causes large amounts of memory use in the broker.  If multiple
clients do this, an out of memory situation can occur and the system may
become unresponsive or the broker will be killed by the operating system.

The fix addresses the problem by limiting the permissible size for CONNECT
packet, and by adding a memory_limit configuration option that allows the
broker to self limit the amount of memory it uses.

The hash of new tarball is not (yet) available through download.php, so use
a locally calculated hash.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit f4df4a18e5dd4702f842e61ee815f13afd93c366)
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/mosquitto/mosquitto.hash
package/mosquitto/mosquitto.mk