Bug 861234 (CVE-2012-4458) - CVE-2012-4458 qpid-cpp: long arrays of zero-width types cause a denial of service
Summary: CVE-2012-4458 qpid-cpp: long arrays of zero-width types cause a denial of ser...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2012-4458
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 824493 845364 918804
Blocks: 849724 851360
TreeView+ depends on / blocked
 
Reported: 2012-09-27 21:35 UTC by Vincent Danen
Modified: 2019-09-29 12:55 UTC (History)
10 users (show)

Fixed In Version: qpid-cpp 0.21
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2013-03-06 22:23:45 UTC


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2013:0561 normal SHIPPED_LIVE Moderate: Red Hat Enterprise MRG Messaging 2.3 security update 2013-03-06 23:48:13 UTC
Red Hat Product Errata RHSA-2013:0562 normal SHIPPED_LIVE Moderate: Red Hat Enterprise MRG Messaging 2.3 security update 2013-03-06 23:47:57 UTC

Description Vincent Danen 2012-09-27 21:35:50 UTC
It was discovered that the AMQP type decoder was exposed pre-authentication because it was possible to send arbitrary types in the client-properties map in a connection.start-ok message.  This is used to send an array with elements which are all of width zero and thus consume no space on the wire, but need storage after decoding by the server.  On some systems, a suitably chosen SIZE value triggers the OOM killer and terminates the server process permanently.


Acknowledgements:

This issue was discovered by Florian Weimer of the Red Hat Product Security Team.

Comment 1 Vincent Danen 2013-03-06 16:58:57 UTC
This is corrected upstream:

https://svn.apache.org/viewvc?view=revision&revision=1453031


External References:

https://issues.apache.org/jira/browse/QPID-4629

Comment 2 errata-xmlrpc 2013-03-06 18:50:52 UTC
This issue has been addressed in following products:

  MRG for RHEL-6 v.2

Via RHSA-2013:0562 https://rhn.redhat.com/errata/RHSA-2013-0562.html

Comment 3 errata-xmlrpc 2013-03-06 18:52:04 UTC
This issue has been addressed in following products:

  MRG for RHEL-5 v. 2

Via RHSA-2013:0561 https://rhn.redhat.com/errata/RHSA-2013-0561.html

Comment 4 Vincent Danen 2013-03-06 22:13:35 UTC
Created qpid-cpp tracking bugs for this issue

Affects: fedora-all [bug 918804]


Note You need to log in before you can comment on or make changes to this bug.