PT-2019-19841 · Fluent Bit · Fluent-Bit

Publicado

2019-03-13

·

Atualizado

2021-07-21

·

CVE-2019-9749

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Fluent Bit versions through 1.0.4
Description An issue in the MQTT input plugin, when acting as an MQTT broker, mishandles incoming network messages. After processing a crafted packet, the mqtt packet drop function executes the memmove() function with a negative size parameter, leading to a crash of the Fluent Bit server via a SIGSEGV signal.
Recommendations For Fluent Bit versions through 1.0.4, consider disabling the MQTT input plugin until a patch is available to prevent the server from crashing due to crafted network messages.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-9749

Produtos afetados

Fluent-Bit