Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-15699

Опубликовано: 13 фев. 2018
Источник: redhat
CVSS3: 6
EPSS Низкий

Описание

A Denial of Service vulnerability was found in Apache Qpid Dispatch Router versions 0.7.0 and 0.8.0. To exploit this vulnerability, a remote user must be able to establish an AMQP connection to the Qpid Dispatch Router and send a specifically crafted AMQP frame which will cause it to segfault and shut down.

Меры по смягчению последствий

To protect against this vulnerability, users need to ensure the interconnect route endpoints are protected by authentication. Please refer to official documentation on how to secure the endpoints: https://access.redhat.com/documentation/en-us/red_hat_jboss_amq/7.0/html-single/using_amq_interconnect/#security-1

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss A-MQ 6InterconnectOut of support scope
Red Hat Satellite 6.3 for RHEL 7candlepinFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7foremanFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7foreman-bootloaders-redhatFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7foreman-discovery-imageFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7foreman-installerFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7foreman-proxyFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7foreman-selinuxFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7hieraFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7katelloFixedRHSA-2018:033621.02.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1512724Interconnect: Denial of Service vulnerability in Red Hat JBoss AMQ Interconnect

EPSS

Процентиль: 74%
0.00832
Низкий

6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
почти 8 лет назад

A Denial of Service vulnerability was found in Apache Qpid Dispatch Router versions 0.7.0 and 0.8.0. To exploit this vulnerability, a remote user must be able to establish an AMQP connection to the Qpid Dispatch Router and send a specifically crafted AMQP frame which will cause it to segfault and shut down.

CVSS3: 6.5
debian
почти 8 лет назад

A Denial of Service vulnerability was found in Apache Qpid Dispatch Ro ...

CVSS3: 6.5
github
больше 3 лет назад

A Denial of Service vulnerability was found in Apache Qpid Dispatch Router versions 0.7.0 and 0.8.0. To exploit this vulnerability, a remote user must be able to establish an AMQP connection to the Qpid Dispatch Router and send a specifically crafted AMQP frame which will cause it to segfault and shut down.

EPSS

Процентиль: 74%
0.00832
Низкий

6 Medium

CVSS3