Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-0203

Опубликовано: 13 янв. 2015
Источник: redhat
CVSS2: 2.9
EPSS Средний

Описание

The qpidd broker in Apache Qpid 0.30 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via an AMQP message with (1) an invalid range in a sequence set, (2) content-bearing methods other than message-transfer, or (3) a session-gap control before a corresponding session-attach.

A flaw was found in the way the Qpid daemon (qpidd) processed certain protocol sequences. An unauthenticated attacker able to send a specially crafted protocol sequence set could use this flaw to crash qpidd.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6qpid-cppWill not fix
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7qpid-cppWill not fix
MRG for RHEL-5 v. 2qpid-cpp-mrgFixedRHSA-2015:066209.03.2015
MRG for RHEL-6 v.3python-qpidFixedRHSA-2015:070719.03.2015
MRG for RHEL-6 v.3qpid-cppFixedRHSA-2015:070719.03.2015
MRG for RHEL-6 v.3qpid-qmfFixedRHSA-2015:070719.03.2015
MRG Messaging v.3 for RHEL-7libdbFixedRHSA-2015:070819.03.2015
MRG Messaging v.3 for RHEL-7python-qpidFixedRHSA-2015:070819.03.2015
MRG Messaging v.3 for RHEL-7qpid-cppFixedRHSA-2015:070819.03.2015
MRG Messaging v.3 for RHEL-7qpid-qmfFixedRHSA-2015:070819.03.2015

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1181721qpid-cpp: 3 qpidd DoS issues in AMQP 0-10 protocol handling

EPSS

Процентиль: 95%
0.17096
Средний

2.9 Low

CVSS2

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

The qpidd broker in Apache Qpid 0.30 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via an AMQP message with (1) an invalid range in a sequence set, (2) content-bearing methods other than message-transfer, or (3) a session-gap control before a corresponding session-attach.

CVSS3: 6.5
nvd
больше 7 лет назад

The qpidd broker in Apache Qpid 0.30 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via an AMQP message with (1) an invalid range in a sequence set, (2) content-bearing methods other than message-transfer, or (3) a session-gap control before a corresponding session-attach.

CVSS3: 6.5
debian
больше 7 лет назад

The qpidd broker in Apache Qpid 0.30 and earlier allows remote authent ...

CVSS3: 6.5
github
больше 3 лет назад

The qpidd broker in Apache Qpid 0.30 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via an AMQP message with (1) an invalid range in a sequence set, (2) content-bearing methods other than message-transfer, or (3) a session-gap control before a corresponding session-attach.

EPSS

Процентиль: 95%
0.17096
Средний

2.9 Low

CVSS2

Уязвимость CVE-2015-0203