Vulnerability Name: | CVE-2012-2145 (CCN-78730) | ||||||||||||||||||||||||||||||||||||
Assigned: | 2012-04-24 | ||||||||||||||||||||||||||||||||||||
Published: | 2012-04-24 | ||||||||||||||||||||||||||||||||||||
Updated: | 2017-08-29 | ||||||||||||||||||||||||||||||||||||
Summary: | Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of incomplete connections. | ||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.7 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-399 | ||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||||||
References: | Source: CCN Type: Apache Web Site Qpid Source: MITRE Type: CNA CVE-2012-2145 Source: CCN Type: RHSA-2012-1269 Moderate: qpid security, bug fix, and enhancement update Source: REDHAT Type: UNKNOWN RHSA-2012:1269 Source: CCN Type: RHSA-2012-1277 Moderate: Red Hat Enterprise MRG Messaging 2.2 update Source: REDHAT Type: UNKNOWN RHSA-2012:1277 Source: CCN Type: SA50573 Apache Qpid Incomplete Client Connection Handling Broker Denial of Service Vulnerability Source: SECUNIA Type: Vendor Advisory 50573 Source: SECUNIA Type: Vendor Advisory 50698 Source: SECUNIA Type: Vendor Advisory 50699 Source: CCN Type: Red Hat Web Site Enterprise MRG Source: BID Type: UNKNOWN 55608 Source: CCN Type: BID-55608 Apache Qpid (qpidd) Denial of Service Vulnerability Source: MISC Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=817175 Source: XF Type: UNKNOWN apache-qpid-broker-dos(78730) Source: XF Type: UNKNOWN apache-qpid-broker-dos(78730) Source: MISC Type: UNKNOWN https://issues.apache.org/jira/browse/QPID-2616 Source: CCN Type: QPID-4021 Badly behaved clients can still clog up the broker Source: MISC Type: UNKNOWN https://issues.apache.org/jira/browse/QPID-4021 | ||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
BACK |