Vulnerability Description
The serializing/deserializing functions in the qpid::framing::Buffer class in Apache Qpid 0.20 and earlier allow remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors. NOTE: this issue could also trigger an out-of-bounds read, but it might not trigger a crash.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Qpid | <= 0.20 |
Related Weaknesses (CWE)
References
- http://svn.apache.org/viewvc?view=revision&revision=1453031Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=861242
- https://issues.apache.org/jira/browse/QPID-4629
- https://issues.apache.org/jira/issues/?jql=fixVersion%20%3D%20%220.21%22%20AND%2
- http://svn.apache.org/viewvc?view=revision&revision=1453031Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=861242
- https://issues.apache.org/jira/browse/QPID-4629
- https://issues.apache.org/jira/issues/?jql=fixVersion%20%3D%20%220.21%22%20AND%2
FAQ
What is CVE-2012-4460?
CVE-2012-4460 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The serializing/deserializing functions in the qpid::framing::Buffer class in Apache Qpid 0.20 and earlier allow remote attackers to cause a denial of service (assertion failure and daemon exit) via u...
How severe is CVE-2012-4460?
CVE-2012-4460 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-4460?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Qpid.