CVE-2017-15701
01.12.2017, 15:29
In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthenticated attacker could exploit this to cause the broker to exhaust all available memory and eventually terminate. Older AMQP protocols are not affected.Enginsight
Vendor | Product | Version |
---|---|---|
apache | qpid_broker-j | 6.1.0 ≤ 𝑥 ≤ 6.1.4 |
𝑥
= Vulnerable software versions
References