mosquitto: security bump to version 1.4.12
authorPeter Korsgaard <peter@korsgaard.com>
Mon, 29 May 2017 21:19:59 +0000 (23:19 +0200)
committerPeter Korsgaard <peter@korsgaard.com>
Tue, 30 May 2017 06:58:28 +0000 (08:58 +0200)
commit9e9dee25346f861f3276a4c2ab21c98b8caf88a7
tree662bec4ddc69fce3f915fc52418d16a5a25dd9af
parent27e0626e99e79655b949e13a16ebdda28c0faca2
mosquitto: security bump to version 1.4.12

Fixes CVE-2017-7650: Pattern based ACLs can be bypassed by clients that set
their username/client id to ‘#’ or ‘+’.  This allows locally or remotely
connected clients to access MQTT topics that they do have the rights to.
The same issue may be present in third party authentication/access control
plugins for Mosquitto.

For more details, see:
https://mosquitto.org/2017/05/security-advisory-cve-2017-7650/

Remove 0001-Remove-lanl-when-WITH_ADNS-is-unset.patch as that patch is now
upstream.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/mosquitto/0001-Remove-lanl-when-WITH_ADNS-is-unset.patch [deleted file]
package/mosquitto/mosquitto.hash
package/mosquitto/mosquitto.mk