GHSA-9wcx-326r-7j7w
Dashboard / Vulnerabilities / GHSA-9wcx-326r-7j7w
Summary: Denial of Service in Apache ActiveMQ
Details: Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.
References: https://nvd.nist.gov/vuln/detail/CVE-2011-4905, https://github.com/apache/activemq/commit/3a71f8e33d0309cb0ca5b5758a8f251da205e757, https://github.com/apache/activemq/commit/9df9d3e89140b7329654ad5675259ec6f0c4b3a7, https://github.com/apache/activemq/commit/da7f9962c640666a743675085922bf75a656f81b, https://github.com/apache/activemq, https://issues.apache.org/jira/browse/AMQ-1928, https://issues.apache.org/jira/browse/AMQ-3294, http://openwall.com/lists/oss-security/2011/12/25/2, http://openwall.com/lists/oss-security/2011/12/25/6, http://svn.apache.org/viewvc?view=revision&revision=1209700, http://svn.apache.org/viewvc?view=revision&revision=1211844
Affected packages
Package
Name: org.apache.activemq:activemq-core
Purl: pkg:maven/org.apache.activemq/activemq-core
Affected ranges
Type: ECOSYSTEM
Events:
