Lucene search

K
cve[email protected]CVE-2012-4459
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-4459

2022-10-0316:15:32
CWE-189
web.nvd.nist.gov
23
cve-2012-4459
apache qpid
integer overflow
denial of service
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.8 Medium

AI Score

Confidence

High

0.01 Low

EPSS

Percentile

83.6%

Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (crash) via a crafted message, which triggers an out-of-bounds read.

Affected configurations

NVD
Node
apacheqpidRange0.20
OR
apacheqpidMatch0.5
OR
apacheqpidMatch0.6
OR
apacheqpidMatch0.7
OR
apacheqpidMatch0.8
OR
apacheqpidMatch0.9
OR
apacheqpidMatch0.10
OR
apacheqpidMatch0.11
OR
apacheqpidMatch0.12
OR
apacheqpidMatch0.13
OR
apacheqpidMatch0.14
OR
apacheqpidMatch0.15
OR
apacheqpidMatch0.16
OR
apacheqpidMatch0.17
OR
apacheqpidMatch0.18
OR
apacheqpidMatch0.19

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.8 Medium

AI Score

Confidence

High

0.01 Low

EPSS

Percentile

83.6%