Resource exhaustion in ActiveMQ - CVE-2019-0222
Published: July 22, 2019
Vulnerability identifier: #VU19300
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0222
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error when processing corrupt MQTT frames. A remote attacker can consume all memory resources on the system and perform a denial of service (DoS) attack.
Affected software
ActiveMQ
Jazz for Service Management
Oracle Communications Diameter Signaling Router (DSR)
Enterprise Manager Base Platform
AMQ Broker
Identity Manager Connector
Oracle Enterprise Repository
Stream Analytics
Ubuntu
libmqtt-client-java (Ubuntu package)
Jazz for Service Management
Oracle Communications Diameter Signaling Router (DSR)
Enterprise Manager Base Platform
AMQ Broker
Identity Manager Connector
Oracle Enterprise Repository
Stream Analytics
Ubuntu
libmqtt-client-java (Ubuntu package)
How to mitigate CVE-2019-0222
Install updates from vendor's website.
ActiveMQ - update to 5.15.9
Jazz for Service Management - update to 1.1.3.25
AMQ Broker - addressed in versions 7.4.3, 7.6
Stream Analytics - update to 19.1.0.0.1
libmqtt-client-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.14-1+deb10u1build0.20.04.1
Jazz for Service Management - update to 1.1.3.25
AMQ Broker - addressed in versions 7.4.3, 7.6
Stream Analytics - update to 19.1.0.0.1
libmqtt-client-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.14-1+deb10u1build0.20.04.1
External References
- http://activemq.apache.org/security-advisories.data/CVE-2019-0222-announcement.txt
- http://www.openwall.com/lists/oss-security/2019/03/27/2
- https://lists.apache.org/thread.html/03f91b1fb85686a848cee6b90112cf6059bd1b21b23bacaa11a962e1@%3Cdev.activemq.apache.org%3E
- https://lists.apache.org/thread.html/2b5c0039197a4949f29e1e2c9441ab38d242946b966f61c110808bcc@%3Ccommits.activemq.apache.org%3E
- https://lists.apache.org/thread.html/71640324661c1b6d0b6708bd4fb20170e1b979370a4b8cddc4f8d485@%3Cdev.activemq.apache.org%3E
- https://lists.apache.org/thread.html/7da9636557118178b1690ba0af49c8a7b7b97d925218b5774622f488@%3Cusers.activemq.apache.org%3E
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2@%3Ccommits.activemq.apache.org%3E
- https://lists.apache.org/thread.html/d1e334bd71d6e68462c62c726fe6db565c7a6283302f9c1feed087fa@%3Ccommits.activemq.apache.org%3E
- https://lists.apache.org/thread.html/fcbe6ad00f1de142148c20d813fae3765dc4274955e3e2f3ca19ff7b@%3Cdev.activemq.apache.org%3E
- https://security.netapp.com/advisory/ntap-20190502-0006/
Related Security Bulletins
- Denial of service in Apache ActiveMQ
- Multiple vulnerabilities in Red Hat AMQ Broker
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router (DSR)
- Multiple vulnerabilities in Identity Manager Connector
- Multiple vulnerabilities in Stream Analytics
- Ubuntu update for mqtt-client
- Multiple vulnerabilities in AMQ Broker 7.4
- Resource exhaustion in Oracle Enterprise Repository
- Multiple vulnerabilities in Enterprise Manager Base Platform
- Multiple vulnerabilities in IBM Jazz for Service Management