First published: Tue Feb 25 2020(Updated: )
Red Hat AMQ Clients enable connecting, sending, and receiving messages over the AMQP 1.0 wire transport protocol to or from AMQ Broker 6 and 7.<br>This update provides various bug fixes and enhancements in addition to the client package versions previously released on Red Hat Enterprise Linux 6, 7, and 8.<br>Security Fix(es):<br><li> netty: HTTP request smuggling (CVE-2019-20444)</li> <li> netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header (CVE-2019-20445)</li> <li> netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling (CVE-2020-7238)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/nodejs-rhea | <1.0.16-1.el8 | 1.0.16-1.el8 |
redhat/qpid-proton | <0.30.0-3.el8 | 0.30.0-3.el8 |
redhat/nodejs-rhea | <1.0.16-1.el8 | 1.0.16-1.el8 |
redhat/python-qpid-proton-docs | <0.30.0-3.el8 | 0.30.0-3.el8 |
redhat/python3-qpid-proton | <0.30.0-3.el8 | 0.30.0-3.el8 |
redhat/python3-qpid-proton-debuginfo | <0.30.0-3.el8 | 0.30.0-3.el8 |
redhat/qpid-proton-c | <0.30.0-3.el8 | 0.30.0-3.el8 |
redhat/qpid-proton-c-debuginfo | <0.30.0-3.el8 | 0.30.0-3.el8 |
redhat/qpid-proton-c-devel | <0.30.0-3.el8 | 0.30.0-3.el8 |
redhat/qpid-proton-c-docs | <0.30.0-3.el8 | 0.30.0-3.el8 |
redhat/qpid-proton-cpp | <0.30.0-3.el8 | 0.30.0-3.el8 |
redhat/qpid-proton-cpp-debuginfo | <0.30.0-3.el8 | 0.30.0-3.el8 |
redhat/qpid-proton-cpp-devel | <0.30.0-3.el8 | 0.30.0-3.el8 |
redhat/qpid-proton-cpp-docs | <0.30.0-3.el8 | 0.30.0-3.el8 |
redhat/qpid-proton-debuginfo | <0.30.0-3.el8 | 0.30.0-3.el8 |
redhat/qpid-proton-debugsource | <0.30.0-3.el8 | 0.30.0-3.el8 |
redhat/qpid-proton-tests | <0.30.0-3.el8 | 0.30.0-3.el8 |
redhat/qpid-proton | <0.30.0-2.el7 | 0.30.0-2.el7 |
redhat/python-qpid-proton | <0.30.0-2.el7 | 0.30.0-2.el7 |
redhat/python-qpid-proton-docs | <0.30.0-2.el7 | 0.30.0-2.el7 |
redhat/qpid-proton-c | <0.30.0-2.el7 | 0.30.0-2.el7 |
redhat/qpid-proton-c-devel | <0.30.0-2.el7 | 0.30.0-2.el7 |
redhat/qpid-proton-c-docs | <0.30.0-2.el7 | 0.30.0-2.el7 |
redhat/qpid-proton-cpp | <0.30.0-2.el7 | 0.30.0-2.el7 |
redhat/qpid-proton-cpp-devel | <0.30.0-2.el7 | 0.30.0-2.el7 |
redhat/qpid-proton-cpp-docs | <0.30.0-2.el7 | 0.30.0-2.el7 |
redhat/qpid-proton-debuginfo | <0.30.0-2.el7 | 0.30.0-2.el7 |
redhat/qpid-proton-tests | <0.30.0-2.el7 | 0.30.0-2.el7 |
redhat/qpid-proton | <0.30.0-4.el6_10 | 0.30.0-4.el6_10 |
redhat/python-qpid-proton | <0.30.0-4.el6_10 | 0.30.0-4.el6_10 |
redhat/python-qpid-proton-docs | <0.30.0-4.el6_10 | 0.30.0-4.el6_10 |
redhat/qpid-proton-c | <0.30.0-4.el6_10 | 0.30.0-4.el6_10 |
redhat/qpid-proton-c-devel | <0.30.0-4.el6_10 | 0.30.0-4.el6_10 |
redhat/qpid-proton-c-docs | <0.30.0-4.el6_10 | 0.30.0-4.el6_10 |
redhat/qpid-proton-cpp | <0.30.0-4.el6_10 | 0.30.0-4.el6_10 |
redhat/qpid-proton-cpp-devel | <0.30.0-4.el6_10 | 0.30.0-4.el6_10 |
redhat/qpid-proton-cpp-docs | <0.30.0-4.el6_10 | 0.30.0-4.el6_10 |
redhat/qpid-proton-debuginfo | <0.30.0-4.el6_10 | 0.30.0-4.el6_10 |
redhat/qpid-proton-tests | <0.30.0-4.el6_10 | 0.30.0-4.el6_10 |
redhat/python-qpid-proton | <0.30.0-4.el6_10 | 0.30.0-4.el6_10 |
redhat/qpid-proton-c | <0.30.0-4.el6_10 | 0.30.0-4.el6_10 |
redhat/qpid-proton-c-devel | <0.30.0-4.el6_10 | 0.30.0-4.el6_10 |
redhat/qpid-proton-cpp | <0.30.0-4.el6_10 | 0.30.0-4.el6_10 |
redhat/qpid-proton-cpp-devel | <0.30.0-4.el6_10 | 0.30.0-4.el6_10 |
redhat/qpid-proton-debuginfo | <0.30.0-4.el6_10 | 0.30.0-4.el6_10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.