Bug 25902

Summary: mosquitto new security issue(s) fixed upstream in 1.6.2
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: David GEIGER <geiger.david68210>
Status: RESOLVED DUPLICATE QA Contact: Sec team <security>
Severity: normal    
Priority: Normal    
Version: 7   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: mosquitto-1.6.0-1.mga7.src.rpm CVE:
Status comment:

Description David Walser 2019-12-19 18:16:35 CET
Fedora has issued an advisory on May 11:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/2BTXFZTM5ZLXR6W3GRIYELKTHAYEFBGT/

I recommend updating to the latest, as well as updating periodically, as this software seems to have a lot of security issues.
Comment 1 David GEIGER 2019-12-20 22:54:16 CET
Done for mga7 updating to latest 1.6.8 release!
Comment 2 David Walser 2019-12-21 02:24:37 CET
Thanks David.  Sophie is outdated and somehow I missed that we updated to 1.6.6 already for another security issue.  I'll close this bug and open a new one for the 1.6.8 update.

*** This bug has been marked as a duplicate of bug 25728 ***

Resolution: (none) => DUPLICATE
Status: NEW => RESOLVED