Release date:
Updated on:
Affected Systems:
RedHat Enterprise Linux Workstation 6
RedHat Enterprise Linux Server 6
RedHat Enterprise Linux Desktop 6
Apache Group Qpid
RedHat MRG Messaging for RHEL Server 2
RedHat MRG Management RHEL 5 Server
Description:
--------------------------------------------------------------------------------
Bugtraq id: 55608
Cve id: CVE-2012-2145
Apache Qpid (Open Source AMQP Messaging) is a cross-platform enterprise communication solution that implements the Advanced Message Queue Protocol.
Apache Qpid (qpidd) 0.17 and other versions have a denial of service vulnerability when handling inbound client connections. Attackers can exploit this vulnerability to cause the client to open too many connections and reject legal connection requests.
<* Source: Vincent Danen
Link: http://secunia.com/advisories/50573/
Badly behaved clients can still clog up the broker
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.apache.org