Release date:
Updated on:
Affected Systems:
Apache Group Qpid 0.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53305
Cve id: CVE-2011-3620
Apache Qpid (Open Source AMQP Messaging) is a cross-platform enterprise communication solution that implements the Advanced Message Queue Protocol.
Apache Qpid 0.12 does not verify the SASL certificate password when connecting to the cluster through the cluster user name. It can access the cluster through malicious proxy.
<* Source: Red Hat
Link: http://secunia.com/advisories/49000/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://httpd.apache.org/