sys/ssl/SslSocket.cpp in qpidd in Apache Qpid, as used in Red Hat Enterprise MRG before 1.2.2 and other products, when SSL is enabled, allows remote attackers to cause a denial of service (daemon outage) by connecting to the SSL port but not participating in an SSL handshake.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Qpid | Apache | 0.5 (including) | 0.5 (including) |
Qpid | Apache | 0.6 (including) | 0.6 (including) |
Messaging Base for MRG on RHEL-4 | RedHat | qpidc-0:0.5.752581-42.el4 | * |
Messaging for MRG on RHEL-4 | RedHat | qpidc-0:0.5.752581-42.el4 | * |
Messaging for MRG on RHEL-4 | RedHat | rhm-0:0.5.3206-36.el4 | * |
MRG for RHEL-5 | RedHat | qpidc-0:0.5.752581-42.el5 | * |
MRG for RHEL-5 | RedHat | rhm-0:0.5.3206-36.el5 | * |