qpid: large messaages cause crash when using digest-md5 and security layer
Published Nov 9, 2019
6.5
MEDIUMCVSS 3.1
EPSS 2.56%
Description
qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use .
Affected products
-
- Version 1.0StatusaffectedConstraints-
- Version
No data.
MRG for RHEL-5
classads-0:1.0.4-1.el5
Fixed · RHEA-2009:1633
MRG for RHEL-5
condor-0:7.4.1-0.7.el5
Fixed · RHEA-2009:1633
MRG for RHEL-5
condor-ec2-enhanced-0:1.0-18.el5
Fixed · RHEA-2009:1633
MRG for RHEL-5
condor-ec2-enhanced-hooks-0:1.0-19.el5
Fixed · RHEA-2009:1633
MRG for RHEL-5
condor-job-hooks-0:1.0-13.el5
Fixed · RHEA-2009:1633
MRG for RHEL-5
condor-low-latency-0:1.0-21.el5
Fixed · RHEA-2009:1633
MRG for RHEL-5
condor-remote-configuration-0:1.0-23.el5
Fixed · RHEA-2009:1633
MRG for RHEL-5
mrg-grid-docs-0:1.2-1.el5
Fixed · RHEA-2009:1633
MRG for RHEL-5
python-qpid-0:0.5.752581-4.el5
Fixed · RHEA-2009:1633
MRG for RHEL-5
qpid-java-0:0.5.751061-9.el5
Fixed · RHEA-2009:1633
MRG for RHEL-5
qpidc-0:0.5.752581-34.el5
Fixed · RHEA-2009:1633
MRG for RHEL-5
rhm-0:0.5.3206-27.el5
Fixed · RHEA-2009:1633
MRG for RHEL-5
rhm-docs-0:0.5.756148-2.el5
Fixed · RHEA-2009:1633
MRG for RHEL-5
sesame-0:0.4.3153-2.el5
Fixed · RHEA-2009:1633
| Product | Package | State | Advisory |
|---|---|---|---|
| MRG for RHEL-5 | classads-0:1.0.4-1.el5 | Fixed | RHEA-2009:1633 |
| MRG for RHEL-5 | condor-0:7.4.1-0.7.el5 | Fixed | RHEA-2009:1633 |
| MRG for RHEL-5 | condor-ec2-enhanced-0:1.0-18.el5 | Fixed | RHEA-2009:1633 |
| MRG for RHEL-5 | condor-ec2-enhanced-hooks-0:1.0-19.el5 | Fixed | RHEA-2009:1633 |
| MRG for RHEL-5 | condor-job-hooks-0:1.0-13.el5 | Fixed | RHEA-2009:1633 |
| MRG for RHEL-5 | condor-low-latency-0:1.0-21.el5 | Fixed | RHEA-2009:1633 |
| MRG for RHEL-5 | condor-remote-configuration-0:1.0-23.el5 | Fixed | RHEA-2009:1633 |
| MRG for RHEL-5 | mrg-grid-docs-0:1.2-1.el5 | Fixed | RHEA-2009:1633 |
| MRG for RHEL-5 | python-qpid-0:0.5.752581-4.el5 | Fixed | RHEA-2009:1633 |
| MRG for RHEL-5 | qpid-java-0:0.5.751061-9.el5 | Fixed | RHEA-2009:1633 |
| MRG for RHEL-5 | qpidc-0:0.5.752581-34.el5 | Fixed | RHEA-2009:1633 |
| MRG for RHEL-5 | rhm-0:0.5.3206-27.el5 | Fixed | RHEA-2009:1633 |
| MRG for RHEL-5 | rhm-docs-0:0.5.756148-2.el5 | Fixed | RHEA-2009:1633 |
| MRG for RHEL-5 | sesame-0:0.4.3153-2.el5 | Fixed | RHEA-2009:1633 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2009-5004 Vendor Advisory
- https://access.redhat.com/security/cve/cve-2009-5004 x_refsource_MISCThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=501792 x_refsource_MISCIssue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=642367 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-5004 x_refsource_MISCIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-5004
- https://security-tracker.debian.org/tracker/CVE-2009-5004 x_refsource_MISCThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2009-5004
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2009-5004 | Vendor Advisory | |
| https://access.redhat.com/security/cve/cve-2009-5004 | x_refsource_MISCThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=501792 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=642367 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-5004 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-5004 | ||
| https://security-tracker.debian.org/tracker/CVE-2009-5004 | x_refsource_MISCThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2009-5004 |
Change history (0)
No recorded changes yet.