CVE-2015-5164: Critical severity Pulpproject Qpid vulnerability
Brian Bouterse of Red Hat reports:
The Qpid server on Satellite6 does not properly restrict message types that can be sent from managed content hosts. An attacker with administrative access to a managed content host could send arbitrary messages containing pickle() encoded data which would then be processed on the Satellite6 server.
Other sources
The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative access on a managed content host to execute arbitrary code via a crafted message, related to a pickle processing problem in pulp.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5164?
CVE-2015-5164 has a medium severity rating due to the potential for an attacker with administrative access to exploit the vulnerability.
How do I fix CVE-2015-5164?
To fix CVE-2015-5164, upgrade the Qpid server to the latest version provided by the vendor that addresses this vulnerability.
What software is affected by CVE-2015-5164?
The primary affected software by CVE-2015-5164 is the Qpid server integrated with Red Hat Satellite 6.0.
Can CVE-2015-5164 be exploited remotely?
CVE-2015-5164 requires administrative access on a managed content host, so it cannot be exploited remotely without such access.
What are the potential consequences of CVE-2015-5164?
The consequences of CVE-2015-5164 include the ability for an attacker to send arbitrary messages containing potentially harmful data.