CVE-2015-0203

MEDIUM

Apache Qpid < 0.30 - Authenticated Denial of Service via AMQP Message

Title source: llm
STIX 2.1

Description

The qpidd broker in Apache Qpid 0.30 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via an AMQP message with (1) an invalid range in a sequence set, (2) content-bearing methods other than message-transfer, or (3) a session-gap control before a corresponding session-attach.

References (4)

Core 4
Core References
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHBA-2016:1500
Issue Tracking, Vendor Advisory x_refsource_confirm
https://issues.apache.org/jira/browse/QPID-6310
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72030

Scores

CVSS v3 6.5
EPSS 0.1699
EPSS Percentile 95.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-19
Status published
Products (1)
apache/qpid < 0.30
Published Feb 21, 2018
Tracked Since Feb 18, 2026