A vulnerability was found in AMQ interconnect component that leads to DoS. If the route endpoint is not protected by authentication, if a remote attacker manages to establish an AMQP connection to the interconnect router, he can then send a specifically crafted AMQP frame to the router that will cause the router to segfault and shut down.
Mitigation: To protect against this vulnerability, users need to ensure the interconnect route endpoints are protected by authentication. Please refer to official documentation on how to secure the endpoints: https://access.redhat.com/documentation/en-us/red_hat_jboss_amq/7.0/html-single/using_amq_interconnect/#security-1
Upstream Patches: https://git-wip-us.apache.org/repos/asf?p=qpid-dispatch.git;a=blobdiff;f=src/router_core/connections.c;h=552a083bca997b4d140f48071c3e88eb8e91414d;hp=b796a0051b313d764fd9a56fcc30f723663c7fd1;hb=b6cd034f389968f836668fcdb3f4e49689b08763;hpb=ced41ae3b2eda83ce643e7cd90e14b43f16de6c1 https://git-wip-us.apache.org/repos/asf?p=qpid-dispatch.git;a=blobdiff;f=src/router_core/connections.c;h=2c7200bc58529385207700101924227ee045594b;hp=5b2a8c8926b6532c79c8e1f8bd6fbd7eda3a1731;hb=c8c4587;hpb=8e8c46ac0690dbaafb2082545cdf0d3cfc62033d
Upstream Issue: https://issues.apache.org/jira/browse/DISPATCH-924
This issue has been addressed in the following products: Red Hat Satellite 6.3 for RHEL 7 Via RHSA-2018:0336 https://access.redhat.com/errata/RHSA-2018:0336
This vulnerability is out of security support scope for the following product: * Red Hat JBoss A-MQ 6 Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.