CVE-2012-4460

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
14/03/2013
Last modified:
11/04/2025

Description

The serializing/deserializing functions in the qpid::framing::Buffer class in Apache Qpid 0.20 and earlier allow remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors. NOTE: this issue could also trigger an out-of-bounds read, but it might not trigger a crash.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:qpid:*:*:*:*:*:*:*:* 0.20 (including)
cpe:2.3:a:apache:qpid:0.5:*:*:*:*:*:*:*
cpe:2.3:a:apache:qpid:0.6:*:*:*:*:*:*:*
cpe:2.3:a:apache:qpid:0.7:*:*:*:*:*:*:*
cpe:2.3:a:apache:qpid:0.8:*:*:*:*:*:*:*
cpe:2.3:a:apache:qpid:0.9:*:*:*:*:*:*:*
cpe:2.3:a:apache:qpid:0.10:*:*:*:*:*:*:*
cpe:2.3:a:apache:qpid:0.11:*:*:*:*:*:*:*
cpe:2.3:a:apache:qpid:0.12:*:*:*:*:*:*:*
cpe:2.3:a:apache:qpid:0.13:*:*:*:*:*:*:*
cpe:2.3:a:apache:qpid:0.14:*:*:*:*:*:*:*
cpe:2.3:a:apache:qpid:0.15:*:*:*:*:*:*:*
cpe:2.3:a:apache:qpid:0.16:*:*:*:*:*:*:*
cpe:2.3:a:apache:qpid:0.17:*:*:*:*:*:*:*
cpe:2.3:a:apache:qpid:0.18:*:*:*:*:*:*:*