Apache Qpid CVE-2015-0223 Security Bypass Vulnerability
BID:72319
Info
Apache Qpid CVE-2015-0223 Security Bypass Vulnerability
| Bugtraq ID: | 72319 |
| Class: | Design Error |
| CVE: |
CVE-2015-0223 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 27 2015 12:00AM |
| Updated: | Jul 15 2015 12:58AM |
| Credit: | G. Geshev from MWR Labs. |
| Vulnerable: |
Red Hat MRG Messaging RHEL 6 Server 2 Red Hat MRG Messaging for RHEL Server 2 Red Hat MRG Grid Execute Node for RHEL 6 ComputeNode 2 |
| Not Vulnerable: | |
Discussion
Apache Qpid CVE-2015-0223 Security Bypass Vulnerability
Apache Qpid is prone to a security-bypass vulnerability because it fails to adequately handle user-supplied input.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions. This may aid in further attacks.
Versions prior to Apache Qpid 0.31 are vulnerable.
Apache Qpid is prone to a security-bypass vulnerability because it fails to adequately handle user-supplied input.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions. This may aid in further attacks.
Versions prior to Apache Qpid 0.31 are vulnerable.
Exploit / POC
Apache Qpid CVE-2015-0223 Security Bypass Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Apache Qpid CVE-2015-0223 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.