In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthenticated attacker could exploit this to cause the broker to exhaust all available memory and eventually terminate. Older AMQP protocols are not affected.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://issues.apache.org/jira/browse/QPID-7947 | vendor advisory issue tracking |
https://lists.apache.org/thread.html/4054e1c90993f337eeea24a312841c0661653e673c0ff8e2cd9520fe%40%3Cdev.qpid.apache.org%3E | mailing list |
https://qpid.apache.org/cves/CVE-2017-15701.html | mitigation vendor advisory |
http://www.securityfocus.com/bid/102041 | third party advisory vdb entry |