REDHAT-BUG-642367: Low severity apache qpid vulnerability
It was reported [1], [2] that Apache QPID would crash when a connection was established using DIGEST-MD5 using the security layer. This was corrected upstream by r780719.
[1] https://issues.apache.org/jira/browse/QPID-1819 [2] https://bugzilla.redhat.com/showbug.cgi?id=501792 [3] http://svn.apache.org/viewvc?revision=780719&view=revision
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-642367?
The severity of REDHAT-BUG-642367 is considered critical due to the potential for Apache QPID to crash when a vulnerable connection method is used.
How do I fix REDHAT-BUG-642367?
To fix REDHAT-BUG-642367, update Apache QPID to the latest version that includes the patch from the upstream revision r780719.
What causes the issue in REDHAT-BUG-642367?
REDHAT-BUG-642367 is caused by a crash in Apache QPID when a connection is established using DIGEST-MD5 with the security layer.
Is REDHAT-BUG-642367 a widespread vulnerability?
Yes, REDHAT-BUG-642367 affects all installations of Apache QPID that utilize the DIGEST-MD5 authentication mechanism.
What are the implications of not addressing REDHAT-BUG-642367?
Not addressing REDHAT-BUG-642367 may leave systems vulnerable to crashes and potential denial of service for applications relying on Apache QPID.