CVE-2012-2145
published 2012-09-28CVE-2012-2145: Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
4.24%
89.9th percentile
Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of incomplete connections.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | qpid | <= 0.17 | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f936-v965-g74r: Apache Qpid 0
ghsa_unreviewed·2022-05-17
CVE-2012-2145 [MEDIUM] GHSA-f936-v965-g74r: Apache Qpid 0
Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of incomplete connections.
Red Hat
qpid-cpp: not closing incomplete connections exhausts file descriptors, leading to DoS
vendor_redhat·2012-04-24·CVSS 5.0
CVE-2012-2145 [MEDIUM] qpid-cpp: not closing incomplete connections exhausts file descriptors, leading to DoS
qpid-cpp: not closing incomplete connections exhausts file descriptors, leading to DoS
Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of incomplete connections.
Package: qpid-cpp (Red Hat Enterprise MRG 1) - Will not fix
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2145 qpid-cpp: not closing incomplete connections exhausts file descriptors, leading to DoS [fedora-all]
bugzilla·2012-05-09·CVSS 5.0
CVE-2012-2145 [MEDIUM] CVE-2012-2145 qpid-cpp: not closing incomplete connections exhausts file descriptors, leading to DoS [fedora-all]
CVE-2012-2145 qpid-cpp: not closing incomplete connections exhausts file descriptors, leading to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedorap
Bugzilla
CVE-2012-2145 qpid-cpp: not closing incomplete connections exhausts file descriptors, leading to DoS
bugzilla·2012-04-27·CVSS 5.0
CVE-2012-2145 [MEDIUM] CVE-2012-2145 qpid-cpp: not closing incomplete connections exhausts file descriptors, leading to DoS
CVE-2012-2145 qpid-cpp: not closing incomplete connections exhausts file descriptors, leading to DoS
A flaw was found in the way that qpidd handled incoming connections. If a client application were to send a large number of connections to qpidd, without terminating the connections with an incomplete handshake, qpidd would keep a file descriptor open for each connection. This could lead to excessive resource consumption by qpidd and could also block other legitimate connection requests.
This flaw has also been reported upstream:
https://issues.apache.org/jira/browse/QPID-2616 (RFE for disconnecting clients on incomplete handshakes)
https://issues.apache.org/jira/browse/QPID-4021 (the actual flaw)
Discussion:
To work-around this issue, you can use the iptables connlimit feature to the
http://rhn.redhat.com/errata/RHSA-2012-1269.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1277.htmlhttp://secunia.com/advisories/50573http://secunia.com/advisories/50698http://secunia.com/advisories/50699http://www.securityfocus.com/bid/55608https://bugzilla.redhat.com/show_bug.cgi?id=817175https://exchange.xforce.ibmcloud.com/vulnerabilities/78730https://issues.apache.org/jira/browse/QPID-2616https://issues.apache.org/jira/browse/QPID-4021http://rhn.redhat.com/errata/RHSA-2012-1269.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1277.htmlhttp://secunia.com/advisories/50573http://secunia.com/advisories/50698http://secunia.com/advisories/50699http://www.securityfocus.com/bid/55608https://bugzilla.redhat.com/show_bug.cgi?id=817175https://exchange.xforce.ibmcloud.com/vulnerabilities/78730https://issues.apache.org/jira/browse/QPID-2616https://issues.apache.org/jira/browse/QPID-4021
2012-09-28
Published