CVE Vulnerabilities

CVE-2010-3083

Published: Oct 12, 2010 | Modified: Jul 15, 2021
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu

sys/ssl/SslSocket.cpp in qpidd in Apache Qpid, as used in Red Hat Enterprise MRG before 1.2.2 and other products, when SSL is enabled, allows remote attackers to cause a denial of service (daemon outage) by connecting to the SSL port but not participating in an SSL handshake.

Affected Software

Name Vendor Start Version End Version
Qpid Apache 0.5 (including) 0.5 (including)
Qpid Apache 0.6 (including) 0.6 (including)
Messaging Base for MRG on RHEL-4 RedHat qpidc-0:0.5.752581-42.el4 *
Messaging for MRG on RHEL-4 RedHat qpidc-0:0.5.752581-42.el4 *
Messaging for MRG on RHEL-4 RedHat rhm-0:0.5.3206-36.el4 *
MRG for RHEL-5 RedHat qpidc-0:0.5.752581-42.el5 *
MRG for RHEL-5 RedHat rhm-0:0.5.3206-36.el5 *

References