Denial of Service Vulnerability in Apache Qpid Dispatch Router by Apache
CVE-2017-15699

6.5MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
13 February 2018

Summary

A vulnerability exists in Apache Qpid Dispatch Router versions 0.7.0 and 0.8.0 that could allow a remote attacker to exploit a Denial of Service condition. By establishing an AMQP connection and sending a specially crafted AMQP frame, an attacker can cause the router to segfault, leading to an unexpected shutdown. It is crucial for users of affected versions to apply the necessary security measures to mitigate this vulnerability.

Affected Version(s)

Apache Qpid Dispatch Router Apache Qpid Dispatch Router 0.7.0 and 0.8.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.