First published: Wed Oct 04 2017(Updated: )
It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when receiving an unexpected multicast message. This may result in a heap memory exhaustion, full GC, or OutOfMemoryError.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache ActiveMQ Artemis | <2.4.0 | |
Red Hat HornetQ | <2.4.0 | |
JBoss Enterprise Application Platform | =6.4.0 | |
JBoss Enterprise Application Platform | =7.1.0 | |
Red Hat Enterprise Linux | =7.0 | |
Red Hat Enterprise Linux | =6.0 | |
JBoss Enterprise Application Platform | =6.0.0 | |
Red Hat Enterprise Linux | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12174 is a medium severity vulnerability that can lead to heap memory exhaustion.
To fix CVE-2017-12174, upgrade Apache ActiveMQ Artemis and Redhat HornetQ to versions later than 2.4.0.
CVE-2017-12174 affects Apache ActiveMQ Artemis versions before 2.4.0 and Redhat HornetQ versions before 2.4.0.
If exploited, CVE-2017-12174 may result in OutOfMemoryError due to excessive memory consumption.
Yes, CVE-2017-12174 is specifically related to the use of UDP discovery and JGroups discovery.