CVE-2015-0203
MEDIUMApache Qpid < 0.30 - Authenticated Denial of Service via AMQP Message
Title source: llmDescription
The qpidd broker in Apache Qpid 0.30 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via an AMQP message with (1) an invalid range in a sequence set, (2) content-bearing methods other than message-transfer, or (3) a session-gap control before a corresponding session-attach.
References (4)
Core 4
Core References
Third Party Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHBA-2016:1500
Issue Tracking, Vendor Advisory x_refsource_confirm
https://issues.apache.org/jira/browse/QPID-6310
Third Party Advisory, VDB Entry x_refsource_misc
https://packetstormsecurity.com/files/129941/Apache-Qpid-0.30-Denial-Of-Service.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/72030
Scores
CVSS v3
6.5
EPSS
0.1699
EPSS Percentile
95.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-19
Status
published
Products (1)
apache/qpid
< 0.30
Published
Feb 21, 2018
Tracked Since
Feb 18, 2026