Bug 34116 - mosquitto new security issue CVE-2023-28366
Summary: mosquitto new security issue CVE-2023-28366
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-03-18 15:58 CET by Nicolas Salguero
Modified: 2025-03-20 00:45 CET (History)
3 users (show)

See Also:
Source RPM: mosquitto-2.0.15-2.mga9.src.rpm
CVE: CVE-2023-28366
Status comment: Fixed upstream in 2.0.21


Attachments

Nicolas Salguero 2025-03-18 15:58:59 CET

Status comment: (none) => Fixed upstream in 2.0.21
Source RPM: (none) => mosquitto-2.0.15-2.mga9.src.rpm
CVE: (none) => CVE-2023-28366

Comment 1 Lewis Smith 2025-03-18 21:26:57 CET
DavidG has already put version: 2.0.21 into Cauldron.
Can you do it for M9 too please?

Assignee: bugsquad => geiger.david68210

Comment 2 David GEIGER 2025-03-19 05:59:52 CET
Assigning to QA,

Packages in 9/Core/Updates_testing:
======================
libmosquitto-devel-2.0.21-1.mga9
libmosquitto1-2.0.21-1.mga9
libmosquittopp1-2.0.21-1.mga9
lib64mosquitto-devel-2.0.21-1.mga9
lib64mosquitto1-2.0.21-1.mga9
lib64mosquittopp1-2.0.21-1.mga9
mosquitto-2.0.21-1.mga9

From SRPMS:
mosquitto-2.0.21-1.mga9.src.rpm

Assignee: geiger.david68210 => qa-bugs

Comment 3 Herman Viaene 2025-03-19 15:48:42 CET
MGA9-64 Plasma Wayland on Compaq H000SB
No installation issues.
Tried in vain to get something more out of starting mosquitto -d and the checking its status. Nothing usefull, so OK on clean install as in bugs 29454 and 29024.

Whiteboard: (none) => MGA9-64-OK
CC: (none) => herman.viaene

katnatek 2025-03-19 19:25:01 CET

Keywords: (none) => advisory

Comment 4 Thomas Andrews 2025-03-19 23:22:17 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 5 Mageia Robot 2025-03-20 00:45:32 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0106.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.