qpid-cpp: multiple vulnerabilities
| Package(s): | qpid-cpp | CVE #(s): | CVE-2015-0203 CVE-2015-0223 CVE-2015-0224 | ||||||||||||||||||||||||||||
| Created: | March 10, 2015 | Updated: | June 22, 2015 | ||||||||||||||||||||||||||||
| Description: | From the Red Hat advisory:
It was discovered that the Qpid daemon (qpidd) did not restrict access to anonymous users when the ANONYMOUS mechanism was disallowed. (CVE-2015-0223) Multiple flaws were found in the way the Qpid daemon (qpidd) processed certain protocol sequences. An unauthenticated attacker able to send a specially crafted protocol sequence set could use these flaws to crash qpidd. (CVE-2015-0203, CVE-2015-0224) | ||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||
