Bug 1696012 (CVE-2019-0222)
Summary: | CVE-2019-0222 activemq: Corrupt MQTT frame can cause broker shutdown | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Pedro Sampaio <psampaio> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | agrimm, aileenc, alazarot, anstephe, ataylor, bmaxwell, bmcclain, cdewolf, chazlett, csutherl, darran.lofthouse, dblechte, dfediuck, dimitris, dosoudil, drieden, eedri, etirelli, ganandan, ggaughan, gvarsami, ibek, janstey, java-sig-commits, jawilson, jcoleman, jochrist, jshepherd, jwon, kconner, krathod, kverlaen, ldimaggi, lgao, mgoldboi, michal.skrivanek, myarboro, nwallace, paradhya, pdrozd, pgier, pslavice, psotirop, puntogil, rnetuka, rrajasek, rsvoboda, rsynek, rwagner, rzhang, sbonazzo, sdaley, sherold, s, sthorger, tcunning, tdawson, tkirby, twalsh, vtunka |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | activemq 5.15.9 | Doc Type: | If docs needed, set a value |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2020-03-23 10:32:04 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1696013 | ||
Bug Blocks: | 1696014 |
Description
Pedro Sampaio
2019-04-04 02:51:46 UTC
Created activemq tracking bugs for this issue: Affects: fedora-all [bug 1696013] This flaw is in ActiveMQ 5.x, not ActiveMQ Artemis which is a different codebase based on HornetMQ. This vulnerability is out of security support scope for the following products: * Red Hat JBoss A-MQ 6 * Red Hat JBoss Fuse Service Works 6 * Red Hat JBoss Fuse 6 Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details. Since this is not an issue with ActiveMQ Artemis, JDG and RHSSO are not affected. This vulnerability is out of security support scope for the following products: * JBoss Developer Studio 11 Please refer to https://access.redhat.com/node/4027141 for more details. This issue has been addressed in the following products: Red Hat AMQ Via RHSA-2020:0922 https://access.redhat.com/errata/RHSA-2020:0922 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-0222 This issue has been addressed in the following products: Red Hat AMQ 7.4.3 Via RHSA-2020:1445 https://access.redhat.com/errata/RHSA-2020:1445 |