Oval Definition:oval:com.redhat.rhsa:def:20121269
Revision Date:2012-09-19Version:634
Title:RHSA-2012:1269: qpid security, bug fix, and enhancement update (Moderate)
Description:Apache Qpid is a reliable, cross-platform, asynchronous messaging system that supports the Advanced Message Queuing Protocol (AMQP) in several common programming languages.

  • It was discovered that the Qpid daemon (qpidd) did not allow the number of connections from clients to be restricted. A malicious client could use this flaw to open an excessive amount of connections, preventing other legitimate clients from establishing a connection to qpidd. (CVE-2012-2145)

    To address CVE-2012-2145, new qpidd configuration options were introduced: max-negotiate-time defines the time during which initial protocol negotiation must succeed, connection-limit-per-user and connection-limit-per-ip can be used to limit the number of connections per user and client host IP. Refer to the qpidd manual page for additional details.

  • In addition, the qpid-cpp, qpid-qmf, qpid-tools, and python-qpid packages have been upgraded to upstream version 0.14, which provides support for Red Hat Enterprise MRG 2.2, as well as a number of bug fixes and enhancements over the previous version. (BZ#840053, BZ#840055, BZ#840056, BZ#840058)

    All users of qpid are advised to upgrade to these updated packages, which fix these issues and add these enhancements.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2012-2145
    CVE-2012-2145
    RHSA-2012:1269
    RHSA-2012:1269-01
    RHSA-2012:1269-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • python-qpid is earlier than 0:0.14-11.el6_3
  • AND python-qpid is signed with Red Hat redhatrelease2 key
  • python-qpid-qmf is earlier than 0:0.14-14.el6_3
  • AND python-qpid-qmf is signed with Red Hat redhatrelease2 key
  • qpid-qmf is earlier than 0:0.14-14.el6_3
  • AND qpid-qmf is signed with Red Hat redhatrelease2 key
  • ruby-qpid-qmf is earlier than 0:0.14-14.el6_3
  • AND ruby-qpid-qmf is signed with Red Hat redhatrelease2 key
  • qpid-tools is earlier than 0:0.14-6.el6_3
  • AND qpid-tools is signed with Red Hat redhatrelease2 key
  • qpid-cpp-client is earlier than 0:0.14-22.el6_3
  • AND qpid-cpp-client is signed with Red Hat redhatrelease2 key
  • qpid-cpp-client-ssl is earlier than 0:0.14-22.el6_3
  • AND qpid-cpp-client-ssl is signed with Red Hat redhatrelease2 key
  • qpid-cpp-server is earlier than 0:0.14-22.el6_3
  • AND qpid-cpp-server is signed with Red Hat redhatrelease2 key
  • qpid-cpp-server-ssl is earlier than 0:0.14-22.el6_3
  • AND qpid-cpp-server-ssl is signed with Red Hat redhatrelease2 key
  • BACK