cbcvebase.
CVE-2009-5006
published 2010-10-18

CVE-2009-5006: The SessionAdapter::ExchangeHandlerImpl::checkAlternate function in broker/SessionAdapter.cpp in the C++ Broker component in Apache Qpid before 0.6, as used in…

PriorityP419medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
4.09%
89.5th percentile
The SessionAdapter::ExchangeHandlerImpl::checkAlternate function in broker/SessionAdapter.cpp in the C++ Broker component in Apache Qpid before 0.6, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote authenticated users to cause a denial of service (NULL pointer dereference, daemon crash, and cluster outage) by attempting to modify the alternate of an exchange.

Affected

9 ranges
VendorProductVersion rangeFixed in
apacheqpid<= 0.5
redhatenterprise_mrg<= 1.2.2
redhatenterprise_mrg
redhatenterprise_mrg
redhatenterprise_mrg
redhatenterprise_mrg
redhatenterprise_mrg
redhatenterprise_mrg
redhatenterprise_mrg

CVSS provenance

nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.