CVE-2019-0222
published 2019-03-28CVE-2019-0222: In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
12.36%
95.8th percentile
In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | >= 0 < 5.15.9-1 | 5.15.9-1 |
| apache | activemq | >= 0 < 5.15.9-1 | 5.15.9-1 |
| apache | activemq | >= 0 < 5.15.9-1 | 5.15.9-1 |
| apache | activemq | 5.0.0 – 5.15.8 | — |
| apache | apache_activemq | — | — |
| debian | activemq | < activemq 5.15.9-1 (bookworm) | activemq 5.15.9-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | mqtt-client | < activemq 5.15.9-1 (bookworm) | activemq 5.15.9-1 (bookworm) |
| oracle | communications_diameter_signaling_router | — | — |
| oracle | communications_diameter_signaling_router | — | — |
| oracle | communications_diameter_signaling_router | — | — |
| oracle | communications_diameter_signaling_router | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | enterprise_repository | — | — |
| oracle | goldengate_stream_analytics | < 19.1.0.0.1 | 19.1.0.0.1 |
| oracle | identity_manager_connector | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Control of Generation of Code ('Code Injection') in org.apache.activemq:activemq-client
osv·2019-04-02
CVE-2019-0222 [HIGH] Improper Control of Generation of Code ('Code Injection') in org.apache.activemq:activemq-client
Improper Control of Generation of Code ('Code Injection') in org.apache.activemq:activemq-client
In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
GHSA
Improper Control of Generation of Code ('Code Injection') in org.apache.activemq:activemq-client
ghsa·2019-04-02
CVE-2019-0222 [HIGH] CWE-94 Improper Control of Generation of Code ('Code Injection') in org.apache.activemq:activemq-client
Improper Control of Generation of Code ('Code Injection') in org.apache.activemq:activemq-client
In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
OSV
CVE-2019-0222: In Apache ActiveMQ 5
osv·2019-03-28·CVSS 7.5
CVE-2019-0222 [HIGH] CVE-2019-0222: In Apache ActiveMQ 5
In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
Ubuntu
mqtt-client vulnerability
vendor_ubuntu·2024-03-07
CVE-2019-0222 mqtt-client vulnerability
Title: mqtt-client vulnerability
Summary: mqtt-client could be made to crash if it received specially crafted
input.
It was discovered that mqtt-client incorrectly handled memory while parsing
malformed MQTT frames. An attacker could possibly use this issue to cause a
crash, resulting in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle GoldenGate Risk Matrix: Security (ActiveMQ) — CVE-2019-0222
vendor_oracle·2020-07-15·CVSS 6.5
CVE-2019-0222 [HIGH] Oracle Oracle GoldenGate Risk Matrix: Security (ActiveMQ) — CVE-2019-0222
Oracle Oracle GoldenGate Risk Matrix: Security (ActiveMQ) vulnerability
CVE: CVE-2019-0222
CVSS: 6.5
Protocol: TCP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (Apache ActiveMQ) — CVE-2019-0222
vendor_oracle·2020-04-15·CVSS 7.5
CVE-2019-0222 [HIGH] Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (Apache ActiveMQ) — CVE-2019-0222
Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (Apache ActiveMQ) vulnerability
CVE: CVE-2019-0222
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Red Hat
activemq: Corrupt MQTT frame can cause broker shutdown
vendor_redhat·2019-03-27·CVSS 7.5
CVE-2019-0222 [HIGH] activemq: Corrupt MQTT frame can cause broker shutdown
activemq: Corrupt MQTT frame can cause broker shutdown
In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
Package: activemq (JBoss Developer Studio 11) - Out of support scope
Package: activemq-artemis (Red Hat Decision Manager 7) - Not affected
Package: activemq (Red Hat Fuse 7) - Will not fix
Package: activemq (Red Hat JBoss A-MQ 6) - Out of support scope
Package: activemq-artemis (Red Hat JBoss Data Grid 7) - Not affected
Package: activemq-artemis (Red Hat JBoss Enterprise Application Platform 7) - Not affected
Package: activemq (Red Hat JBoss Fuse 6) - Out of support scope
Package: activemq (Red Hat JBoss Fuse Service Works 6) - Out of support scope
Package: activemq-artemis (Red Hat Process Au
Debian
CVE-2019-0222: activemq - In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to ...
vendor_debian·2019·CVSS 7.5
CVE-2019-0222 [HIGH] CVE-2019-0222: activemq - In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to ...
In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
Scope: local
bookworm: resolved (fixed in 5.15.9-1)
bullseye: resolved (fixed in 5.15.9-1)
sid: resolved (fixed in 5.15.9-1)
trixie: resolved (fixed in 5.15.9-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-0222 activemq: Corrupt MQTT frame can cause broker shutdown [fedora-all]
bugzilla·2019-04-04·CVSS 7.5
CVE-2019-0222 [HIGH] CVE-2019-0222 activemq: Corrupt MQTT frame can cause broker shutdown [fedora-all]
CVE-2019-0222 activemq: Corrupt MQTT frame can cause broker shutdown [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
Bugzilla
CVE-2019-0222 activemq: Corrupt MQTT frame can cause broker shutdown
bugzilla·2019-04-04·CVSS 7.5
CVE-2019-0222 [HIGH] CVE-2019-0222 activemq: Corrupt MQTT frame can cause broker shutdown
CVE-2019-0222 activemq: Corrupt MQTT frame can cause broker shutdown
In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
References:
http://activemq.apache.org/security-advisories.data/CVE-2019-0222-announcement.txt
Discussion:
Created activemq tracking bugs for this issue:
Affects: fedora-all [bug 1696013]
---
This flaw is in ActiveMQ 5.x, not ActiveMQ Artemis which is a different codebase based on HornetMQ.
---
This vulnerability is out of security support scope for the following products:
* Red Hat JBoss A-MQ 6
* Red Hat JBoss Fuse Service Works 6
* Red Hat JBoss Fuse 6
Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.
---
Since this is not an issu
http://activemq.apache.org/security-advisories.data/CVE-2019-0222-announcement.txthttp://www.openwall.com/lists/oss-security/2019/03/27/2http://www.securityfocus.com/bid/107622https://lists.apache.org/thread.html/03f91b1fb85686a848cee6b90112cf6059bd1b21b23bacaa11a962e1%40%3Cdev.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/2b5c0039197a4949f29e1e2c9441ab38d242946b966f61c110808bcc%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/71640324661c1b6d0b6708bd4fb20170e1b979370a4b8cddc4f8d485%40%3Cdev.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/7da9636557118178b1690ba0af49c8a7b7b97d925218b5774622f488%40%3Cusers.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/d1e334bd71d6e68462c62c726fe6db565c7a6283302f9c1feed087fa%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/fcbe6ad00f1de142148c20d813fae3765dc4274955e3e2f3ca19ff7b%40%3Cdev.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r946488fb942fd35c6a6e0359f52504a558ed438574a8f14d36d7dcd7%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/rb698ed085f79e56146ca24ab359c9ef95846618675ea1ef402e04a6d%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/re4672802b0e5ed67c08c9e77057d52138e062f77cc09581b723cf95a%40%3Ccommits.activemq.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/03/msg00004.htmlhttps://lists.debian.org/debian-lts-announce/2021/03/msg00005.htmlhttps://security.netapp.com/advisory/ntap-20190502-0006/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttp://activemq.apache.org/security-advisories.data/CVE-2019-0222-announcement.txthttp://www.openwall.com/lists/oss-security/2019/03/27/2http://www.securityfocus.com/bid/107622https://lists.apache.org/thread.html/03f91b1fb85686a848cee6b90112cf6059bd1b21b23bacaa11a962e1%40%3Cdev.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/2b5c0039197a4949f29e1e2c9441ab38d242946b966f61c110808bcc%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/71640324661c1b6d0b6708bd4fb20170e1b979370a4b8cddc4f8d485%40%3Cdev.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/7da9636557118178b1690ba0af49c8a7b7b97d925218b5774622f488%40%3Cusers.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/d1e334bd71d6e68462c62c726fe6db565c7a6283302f9c1feed087fa%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/fcbe6ad00f1de142148c20d813fae3765dc4274955e3e2f3ca19ff7b%40%3Cdev.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r946488fb942fd35c6a6e0359f52504a558ed438574a8f14d36d7dcd7%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/rb698ed085f79e56146ca24ab359c9ef95846618675ea1ef402e04a6d%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/re4672802b0e5ed67c08c9e77057d52138e062f77cc09581b723cf95a%40%3Ccommits.activemq.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/03/msg00004.htmlhttps://lists.debian.org/debian-lts-announce/2021/03/msg00005.htmlhttps://security.netapp.com/advisory/ntap-20190502-0006/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
2019-03-28
Published