activemq: Corrupt MQTT frame can cause broker shutdown
Published Mar 28, 2019
7.5
HIGHCVSS 3.1
EPSS 12.03%
Description
In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
Affected products
-
- Version Apache ActiveMQ 5.0.0 - 5.15.8StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache | Apache ActiveMQ | n/a |
|
Configuration 2
- n/a
Configuration 3
- 8.0.0
- 8.1
- 8.2
- 8.2.1
- 12.1.0.5.0
- 13.2.0.0.0
- 13.3.0.0.0
- 12.1.3.0.0
- < 19.1.0.0.1
- 9.0
Configuration 4
- 9.0
No data.
Red Hat AMQ
mqtt-client
Fixed · RHSA-2020:0922
Red Hat AMQ 7.4.3
mqtt-client
Fixed · RHSA-2020:1445
JBoss Developer Studio 11
activemq
Out of support scope
Red Hat Decision Manager 7
activemq-artemis
Not affected
Red Hat Fuse 7
activemq
Will not fix
Red Hat JBoss A-MQ 6
activemq
Out of support scope
Red Hat JBoss Data Grid 7
activemq-artemis
Not affected
Red Hat JBoss Enterprise Application Platform 7
activemq-artemis
Not affected
Red Hat JBoss Fuse 6
activemq
Out of support scope
Red Hat JBoss Fuse Service Works 6
activemq
Out of support scope
Red Hat Process Automation 7
activemq-artemis
Not affected
Red Hat Single Sign-On 7
activemq-artemis
Not affected
Red Hat Virtualization 4
eap7-activemq-artemis
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AMQ | mqtt-client | Fixed | RHSA-2020:0922 |
| Red Hat AMQ 7.4.3 | mqtt-client | Fixed | RHSA-2020:1445 |
| JBoss Developer Studio 11 | activemq | Out of support scope | n/a |
| Red Hat Decision Manager 7 | activemq-artemis | Not affected | n/a |
| Red Hat Fuse 7 | activemq | Will not fix | n/a |
| Red Hat JBoss A-MQ 6 | activemq | Out of support scope | n/a |
| Red Hat JBoss Data Grid 7 | activemq-artemis | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | activemq-artemis | Not affected | n/a |
| Red Hat JBoss Fuse 6 | activemq | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | activemq | Out of support scope | n/a |
| Red Hat Process Automation 7 | activemq-artemis | Not affected | n/a |
| Red Hat Single Sign-On 7 | activemq-artemis | Not affected | n/a |
| Red Hat Virtualization 4 | eap7-activemq-artemis | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (37)
- http://activemq.apache.org/security-advisories.data/CVE-2019-0222-announcement.txt x_refsource_CONFIRMMitigationThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/03/27/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/107622 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2019-0222 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1696012 Issue Tracking
- https://github.com/advisories/GHSA-jpv3-g4cc-6vfx Advisory
- https://github.com/apache/activemq/commit/98b9f2e
- https://github.com/apache/activemq/commit/f78c0962ffb46fae3397eed6b7ec1e6e15045031
- https://lists.apache.org/thread.html/03f91b1fb85686a848cee6b90112cf6059bd1b21b23bacaa11a962e1%40%3Cdev.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/03f91b1fb85686a848cee6b90112cf6059bd1b21b23bacaa11a962e1@%3Cdev.activemq.apache.org%3E
- https://lists.apache.org/thread.html/2b5c0039197a4949f29e1e2c9441ab38d242946b966f61c110808bcc%40%3Ccommits.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/2b5c0039197a4949f29e1e2c9441ab38d242946b966f61c110808bcc@%3Ccommits.activemq.apache.org%3E
- https://lists.apache.org/thread.html/71640324661c1b6d0b6708bd4fb20170e1b979370a4b8cddc4f8d485%40%3Cdev.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/71640324661c1b6d0b6708bd4fb20170e1b979370a4b8cddc4f8d485@%3Cdev.activemq.apache.org%3E
- https://lists.apache.org/thread.html/7da9636557118178b1690ba0af49c8a7b7b97d925218b5774622f488%40%3Cusers.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/7da9636557118178b1690ba0af49c8a7b7b97d925218b5774622f488@%3Cusers.activemq.apache.org%3E
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2@%3Ccommits.activemq.apache.org%3E
- https://lists.apache.org/thread.html/d1e334bd71d6e68462c62c726fe6db565c7a6283302f9c1feed087fa%40%3Ccommits.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/d1e334bd71d6e68462c62c726fe6db565c7a6283302f9c1feed087fa@%3Ccommits.activemq.apache.org%3E
- https://lists.apache.org/thread.html/fcbe6ad00f1de142148c20d813fae3765dc4274955e3e2f3ca19ff7b%40%3Cdev.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/fcbe6ad00f1de142148c20d813fae3765dc4274955e3e2f3ca19ff7b@%3Cdev.activemq.apache.org%3E
- https://lists.apache.org/thread.html/r946488fb942fd35c6a6e0359f52504a558ed438574a8f14d36d7dcd7%40%3Ccommits.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r946488fb942fd35c6a6e0359f52504a558ed438574a8f14d36d7dcd7@%3Ccommits.activemq.apache.org%3E
- https://lists.apache.org/thread.html/rb698ed085f79e56146ca24ab359c9ef95846618675ea1ef402e04a6d%40%3Ccommits.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rb698ed085f79e56146ca24ab359c9ef95846618675ea1ef402e04a6d@%3Ccommits.activemq.apache.org%3E
- https://lists.apache.org/thread.html/re4672802b0e5ed67c08c9e77057d52138e062f77cc09581b723cf95a%40%3Ccommits.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/re4672802b0e5ed67c08c9e77057d52138e062f77cc09581b723cf95a@%3Ccommits.activemq.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/03/msg00004.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00005.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-0222
- https://security.netapp.com/advisory/ntap-20190502-0006 x_refsource_CONFIRMThird Party Advisory
- https://web.archive.org/web/20190404065432/http://www.securityfocus.com/bid/107622
- https://www.cve.org/CVERecord?id=CVE-2019-0222
- https://www.oracle.com/security-alerts/cpuapr2020.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html x_refsource_MISCThird Party Advisory
Change history (0)
No recorded changes yet.