REDHAT-BUG-642377: Null Pointer Dereference
It was reported [1], [2] that Apache QPID would crash due to a NULL pointer dereference when a remote, authenticated user attempted to redeclare an existing exchange and add a new alternate exchange. This would result in a denial of service condition of the server. This was corrected upstream by r811188 [3].
[1] https://issues.apache.org/jira/browse/QPID-2080 [2] https://bugzilla.redhat.com/showbug.cgi?id=517751 [3] http://svn.apache.org/viewvc?revision=811188&view=revision
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-642377?
The severity of REDHAT-BUG-642377 is classified as high due to its potential to cause denial of service.
How do I fix REDHAT-BUG-642377?
To fix REDHAT-BUG-642377, update Apache QPID to the latest version where the vulnerability has been patched.
What are the consequences of REDHAT-BUG-642377?
The consequence of REDHAT-BUG-642377 is a crash of the Apache QPID server leading to a denial of service for users.
What versions of Apache QPID are affected by REDHAT-BUG-642377?
REDHAT-BUG-642377 affects certain versions of Apache QPID that allow remote authenticated users to redeclare exchanges.
Is there a workaround for REDHAT-BUG-642377?
Currently, the recommended action for REDHAT-BUG-642377 is to apply the available patches rather than seeking a workaround.