Red Hat Bugzilla – Bug 640006
CVE-2010-3701 MRG: remote authenticated DoS in broker
Last modified: 2015-07-31 08:23:29 EDT
A flaw was discovered in how the MRG broker handled the receipt of large persistent messages. If a remote authenticated user were to send a very large persistent message, the broker could exhaust stack memory, resulting in a segfault of the broker. Subsequent connections to the broker would fail until it was restarted.
Further details of this flaw can be found in bug #634014.
This issue has been addressed in following products: MRG for RHEL-5 Via RHSA-2010:0756 https://rhn.redhat.com/errata/RHSA-2010-0756.html
This issue has been addressed in following products: Messaging for MRG on RHEL-4 Messaging Base for MRG on RHEL-4 Via RHSA-2010:0757 https://rhn.redhat.com/errata/RHSA-2010-0757.html