CVE-2009-5006
Published Oct 18, 2010
Last updated 3 years ago
Overview
- Description
- The SessionAdapter::ExchangeHandlerImpl::checkAlternate function in broker/SessionAdapter.cpp in the C++ Broker component in Apache Qpid before 0.6, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote authenticated users to cause a denial of service (NULL pointer dereference, daemon crash, and cluster outage) by attempting to modify the alternate of an exchange.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4
- Impact score
- 2.9
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:N/I:N/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Social media
- Hype score
- Not currently trending
Evaluator
- Comment
- Per: http://cwe.mitre.org/data/definitions/476.html 'CWE-476: NULL Pointer Dereference'
- Impact
- -
- Solution
- -
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:apache:qpid:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "63A5CF09-B7B3-4E40-8546-11230A9B7755", "versionEndIncluding": "0.5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:redhat:enterprise_mrg:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "059C1E78-7197-4A08-9E1A-138F82F949EE", "versionEndIncluding": "1.2.2" }, { "criteria": "cpe:2.3:o:redhat:enterprise_mrg:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CB4E172C-4FBD-40AA-91F1-2858A74C5483" }, { "criteria": "cpe:2.3:o:redhat:enterprise_mrg:1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4E8A4D28-0EC4-4584-9126-A47003CD06AE" }, { "criteria": "cpe:2.3:o:redhat:enterprise_mrg:1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "12EE56E2-D7B7-4BF6-BC1F-86B8EE77F064" }, { "criteria": "cpe:2.3:o:redhat:enterprise_mrg:1.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5F9A3A7B-4A61-4F2C-A8F9-D428B690294E" }, { "criteria": "cpe:2.3:o:redhat:enterprise_mrg:1.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "73C6E954-7BBE-4214-9407-86322372FCB2" }, { "criteria": "cpe:2.3:o:redhat:enterprise_mrg:1.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ED639614-7AE8-4DDE-9FE3-1554FE59202C" }, { "criteria": "cpe:2.3:o:redhat:enterprise_mrg:1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FD09E081-B714-45A1-ACBB-28D805BFD01C" } ], "operator": "OR" } ], "operator": "AND" } ]