PT-2019-19841 · Fluent Bit · Fluent-Bit

Published

2019-03-13

·

Updated

2021-07-21

·

CVE-2019-9749

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Fluent Bit versions through 1.0.4
Description An issue in the MQTT input plugin, when acting as an MQTT broker, mishandles incoming network messages. After processing a crafted packet, the mqtt packet drop function executes the memmove() function with a negative size parameter, leading to a crash of the Fluent Bit server via a SIGSEGV signal.
Recommendations For Fluent Bit versions through 1.0.4, consider disabling the MQTT input plugin until a patch is available to prevent the server from crashing due to crafted network messages.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-9749

Affected Products

Fluent-Bit