logo

Database

Lack of data validation In org.apache.activemq:activemq-client

Description

Improper Control of Generation of Code ('Code Injection') in org.apache.activemq:activemq-client In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions

References

1. https://github.com/shoucheng3/apache__activemq_CVE-2019-0222_5-15-82. https://github.com/apache/activemq/commit/98b9f2e3. https://github.com/apache/activemq/commit/f78c0962ffb46fae3397eed6b7ec1e6e150450314. https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html5. https://www.oracle.com/security-alerts/cpujul2020.html6. https://www.oracle.com/security-alerts/cpuapr2020.html7. https://web.archive.org/web/20190404065432/http://www.securityfocus.com/bid/1076228. https://security.netapp.com/advisory/ntap-20190502-00069. https://lists.apache.org/thread.html/re4672802b0e5ed67c08c9e77057d52138e062f77cc09581b723cf95a@%3Ccommits.activemq.apache.org%3E10. https://lists.apache.org/thread.html/rb698ed085f79e56146ca24ab359c9ef95846618675ea1ef402e04a6d@%3Ccommits.activemq.apache.org%3E11. https://lists.apache.org/thread.html/r946488fb942fd35c6a6e0359f52504a558ed438574a8f14d36d7dcd7@%3Ccommits.activemq.apache.org%3E12. https://lists.apache.org/thread.html/fcbe6ad00f1de142148c20d813fae3765dc4274955e3e2f3ca19ff7b@%3Cdev.activemq.apache.org%3E13. https://lists.apache.org/thread.html/d1e334bd71d6e68462c62c726fe6db565c7a6283302f9c1feed087fa@%3Ccommits.activemq.apache.org%3E14. https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2@%3Ccommits.activemq.apache.org%3E15. https://lists.apache.org/thread.html/7da9636557118178b1690ba0af49c8a7b7b97d925218b5774622f488@%3Cusers.activemq.apache.org%3E16. https://lists.apache.org/thread.html/71640324661c1b6d0b6708bd4fb20170e1b979370a4b8cddc4f8d485@%3Cdev.activemq.apache.org%3E17. https://lists.apache.org/thread.html/2b5c0039197a4949f29e1e2c9441ab38d242946b966f61c110808bcc@%3Ccommits.activemq.apache.org%3E18. https://lists.apache.org/thread.html/03f91b1fb85686a848cee6b90112cf6059bd1b21b23bacaa11a962e1@%3Cdev.activemq.apache.org%3E19. http://activemq.apache.org/security-advisories.data/CVE-2019-0222-announcement.txt20. http://www.openwall.com/lists/oss-security/2019/03/27/221. http://www.securityfocus.com/bid/107622