Lucene search

K
redhatRedHatRHSA-2020:0601
HistoryFeb 25, 2020 - 3:01 p.m.

(RHSA-2020:0601) Important: AMQ Clients 2.6.0 Release

2020-02-2515:01:50
access.redhat.com
43

0.009 Low

EPSS

Percentile

82.4%

Red Hat AMQ Clients enable connecting, sending, and receiving messages over the AMQP 1.0 wire transport protocol to or from AMQ Broker 6 and 7.

This update provides various bug fixes and enhancements in addition to the client package versions previously released on Red Hat Enterprise Linux 6, 7, and 8.

Security Fix(es):

  • netty: HTTP request smuggling (CVE-2019-20444)

  • netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header (CVE-2019-20445)

  • netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling (CVE-2020-7238)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.