Vulnerability Description
Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (crash) via a crafted message, which triggers an out-of-bounds read.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Qpid | <= 0.20 |
Related Weaknesses (CWE)
References
- http://rhn.redhat.com/errata/RHSA-2013-0561.html
- http://rhn.redhat.com/errata/RHSA-2013-0562.html
- http://secunia.com/advisories/52516Vendor Advisory
- http://svn.apache.org/viewvc?view=revision&revision=1453031Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=861241
- https://issues.apache.org/jira/browse/QPID-4629
- https://issues.apache.org/jira/issues/?jql=fixVersion%20%3D%20%220.21%22%20AND%2
- http://rhn.redhat.com/errata/RHSA-2013-0561.html
- http://rhn.redhat.com/errata/RHSA-2013-0562.html
- http://secunia.com/advisories/52516Vendor Advisory
- http://svn.apache.org/viewvc?view=revision&revision=1453031Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=861241
- https://issues.apache.org/jira/browse/QPID-4629
- https://issues.apache.org/jira/issues/?jql=fixVersion%20%3D%20%220.21%22%20AND%2
FAQ
What is CVE-2012-4459?
CVE-2012-4459 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (crash) via a crafted message, which trigger...
How severe is CVE-2012-4459?
CVE-2012-4459 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-4459?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Qpid.