CVE-2010-3083: Medium severity Apache qpid vulnerability

Published Sep 10, 2010
·
Updated

It was discovered that SSL connections to the MRG broker could easily be blocked. If a client or application initiated a connection to the MRG broker's listening SSL port, the client connection would block access to the port until the SSL handshake completes (or fails). If a client failed to proceed with it, then the thread was never freed to process other connections, denying service to other clients. Only SSL connections were affected by this issue, and SSL support is not enabled by default.

Other sources

sys/ssl/SslSocket.cpp in qpidd in Apache Qpid, as used in Red Hat Enterprise MRG before 1.2.2 and other products, when SSL is enabled, allows remote attackers to cause a denial of service (daemon outage) by connecting to the SSL port but not participating in an SSL handshake.

Affected Software

9 affected components
Apache qpid=0.5
Apache qpid=0.6
redhat Enterprise MRG<=1.2
redhat Enterprise MRG=1.0
redhat Enterprise MRG=1.0.1
redhat Enterprise MRG=1.0.2
redhat Enterprise MRG=1.0.3
redhat Enterprise MRG=1.1.1
redhat Enterprise MRG=1.1.2

Event History

Sep 10, 2010
Data Sourced
via Red Hat·04:42 PM
DescriptionSeverityAffected Software
Oct 12, 2010
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
09:00 PM
DescriptionWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2010-3083?

CVE-2010-3083 has been classified as having medium severity due to its impact on SSL connection handling.

2

How do I fix CVE-2010-3083?

To fix CVE-2010-3083, upgrade to an unaffected version of Apache Qpid or Red Hat Enterprise MRG as specified in the vendor advisories.

3

What software is affected by CVE-2010-3083?

CVE-2010-3083 affects specific versions of Apache Qpid and Red Hat Enterprise MRG.

4

What is the potential impact of CVE-2010-3083?

The potential impact of CVE-2010-3083 is the blocking of SSL connections to the MRG broker, leading to denial of service.

5

Is there a workaround for CVE-2010-3083?

There are no known effective workarounds for CVE-2010-3083; the recommended solution is to apply updates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203