4

CVE-2009-5006

The SessionAdapter::ExchangeHandlerImpl::checkAlternate function in broker/SessionAdapter.cpp in the C++ Broker component in Apache Qpid before 0.6, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote authenticated users to cause a denial of service (NULL pointer dereference, daemon crash, and cluster outage) by attempting to modify the alternate of an exchange.

Data is provided by the National Vulnerability Database (NVD)
ApacheQpid Version <= 0.5
RedhatEnterprise Mrg Version <= 1.2.2
RedhatEnterprise Mrg Version1.0
RedhatEnterprise Mrg Version1.0.1
RedhatEnterprise Mrg Version1.0.2
RedhatEnterprise Mrg Version1.0.3
RedhatEnterprise Mrg Version1.1.1
RedhatEnterprise Mrg Version1.1.2
RedhatEnterprise Mrg Version1.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.47% 0.616
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P