Apache Qpid Multiple Denial of Service

Strike ID:
D15-35n01
CVSS:
6.5 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
False Positive:
f
Variants:
8
Year:
2015

Description

This strike exploits a denial of service vulnerability in Apache Qpid. When sent a session.gap message before a session is established, the exception is not handled properly, resulting in an assertion failure and abnormal program termination. Additionally, handling a session.expected message with certain range values will also result in an assertion failure and abnormal program termination. Successful exploitation will lead to a denial of service condition.

CVE

References

Bid