REDHAT-BUG-642373: Medium severity apache qpid vulnerability
It was reported [1] that Apache QPID would crash when receiving data from a client that is not valid AMQP data, resulting in a shut down of the cluster rather than the client being disconnected. This was corrected upstream by r785788 [2].
[1] https://bugzilla.redhat.com/showbug.cgi?id=506580 [2] http://svn.apache.org/viewvc?revision=785788&view=revision
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-642373?
The severity of REDHAT-BUG-642373 is critical due to potential cluster shutdowns when invalid data is received.
How do I fix REDHAT-BUG-642373?
To fix REDHAT-BUG-642373, update to the latest version of Apache QPID that includes the upstream patch.
What impact does REDHAT-BUG-642373 have on Apache QPID clusters?
REDHAT-BUG-642373 can lead to complete cluster shutdowns instead of gracefully disconnecting clients when invalid AMQP data is received.
Is there a version of Apache QPID that is safe from REDHAT-BUG-642373?
Yes, versions of Apache QPID that incorporate the upstream fix from revision r785788 are safe from REDHAT-BUG-642373.
Can malicious clients exploit REDHAT-BUG-642373?
Yes, malicious clients can exploit REDHAT-BUG-642373 to crash the Apache QPID service, impacting availability.