CVE-2012-2145

Description

Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of incomplete connections.

Risk Information

Base Score
9.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS Score
Exploitation Probability
7.15

Associated Vulnerability

VulnerabilityOS Platform
Qpid update (CESA-2012:1269) qpid-tools-0.14-6.el6_3.noarch.rpmLinux
Qpid update (CESA-2012:1269) python-qpid-0.14-11.el6_3.noarch.rpmLinux
Qpid update (CESA-2012:1269) ruby-qpid-qmf-0.14-14.el6_3.i686.rpmLinux
Qpid update (CESA-2012:1269) ruby-qpid-qmf-0.14-14.el6_3.x86_64.rpmLinux
Qpid update (CESA-2012:1269) python-qpid-qmf-0.14-14.el6_3.i686.rpmLinux
Qpid update (CESA-2012:1269) python-qpid-qmf-0.14-14.el6_3.x86_64.rpmLinux
Qpid update (CESA-2012:1269) qpid-cpp-client-0.14-22.el6_3.i686.rpmLinux
Qpid update (CESA-2012:1269) qpid-cpp-client-0.14-22.el6_3.x86_64.rpmLinux
Qpid update (CESA-2012:1269) qpid-cpp-server-0.14-22.el6_3.i686.rpmLinux
Qpid update (CESA-2012:1269) qpid-cpp-server-0.14-22.el6_3.x86_64.rpmLinux
Qpid update (CESA-2012:1269) qpid-cpp-client-ssl-0.14-22.el6_3.i686.rpmLinux
Qpid update (CESA-2012:1269) qpid-cpp-client-ssl-0.14-22.el6_3.x86_64.rpmLinux
Qpid update (CESA-2012:1269) qpid-cpp-server-ssl-0.14-22.el6_3.i686.rpmLinux
Qpid update (CESA-2012:1269) qpid-cpp-server-ssl-0.14-22.el6_3.x86_64.rpmLinux
(RHSA-2012:1269) Moderate: qpid security, bug fix, and enhancement update python-qpid-0.14-11.el6_3.noarch.rpmLinux
(RHSA-2012:1269) Moderate: qpid security, bug fix, and enhancement update python-qpid-qmf-0.14-14.el6_3.i686.rpmLinux
(RHSA-2012:1269) Moderate: qpid security, bug fix, and enhancement update python-qpid-qmf-0.14-14.el6_3.x86_64.rpmLinux
(RHSA-2012:1269) Moderate: qpid security, bug fix, and enhancement update qpid-cpp-client-0.14-22.el6_3.i686.rpmLinux
(RHSA-2012:1269) Moderate: qpid security, bug fix, and enhancement update qpid-cpp-client-0.14-22.el6_3.x86_64.rpmLinux
(RHSA-2012:1269) Moderate: qpid security, bug fix, and enhancement update qpid-cpp-client-ssl-0.14-22.el6_3.i686.rpmLinux
(RHSA-2012:1269) Moderate: qpid security, bug fix, and enhancement update qpid-cpp-client-ssl-0.14-22.el6_3.x86_64.rpmLinux
(RHSA-2012:1269) Moderate: qpid security, bug fix, and enhancement update qpid-cpp-server-0.14-22.el6_3.i686.rpmLinux
(RHSA-2012:1269) Moderate: qpid security, bug fix, and enhancement update qpid-cpp-server-0.14-22.el6_3.x86_64.rpmLinux
(RHSA-2012:1269) Moderate: qpid security, bug fix, and enhancement update qpid-cpp-server-ssl-0.14-22.el6_3.i686.rpmLinux
(RHSA-2012:1269) Moderate: qpid security, bug fix, and enhancement update qpid-cpp-server-ssl-0.14-22.el6_3.x86_64.rpmLinux
(RHSA-2012:1269) Moderate: qpid security, bug fix, and enhancement update qpid-qmf-0.14-14.el6_3.i686.rpmLinux
(RHSA-2012:1269) Moderate: qpid security, bug fix, and enhancement update qpid-qmf-0.14-14.el6_3.x86_64.rpmLinux
(RHSA-2012:1269) Moderate: qpid security, bug fix, and enhancement update qpid-tools-0.14-6.el6_3.noarch.rpmLinux
(RHSA-2012:1269) Moderate: qpid security, bug fix, and enhancement update ruby-qpid-qmf-0.14-14.el6_3.i686.rpmLinux
(RHSA-2012:1269) Moderate: qpid security, bug fix, and enhancement update ruby-qpid-qmf-0.14-14.el6_3.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234