CVE-2014-3576

high
Published 2015-08-14 ยท Modified 2024-02-16
CVSS v3
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
7.5

Description

Improper Neutralization of Special Elements used in an OS Command in Apache ActiveMQ

Predictions

Exploit likelihood
83%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker ยท View original โ†— ยท DFSG

CVE-2014-3576 NameCVE-2014-3576 DescriptionThe processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)โ€ฆ

CVE-2014-3576

NameCVE-2014-3576
DescriptionThe processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-3330-1
Debian Bugs792857

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
activemq (PTS)bullseye5.16.1-1fixed
bullseye (security)5.16.1-1+deb11u2fixed
bookworm, bookworm (security)5.17.2+dfsg-2+deb12u1fixed
sid, trixie5.17.6+dfsg-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
activemqsourcewheezy5.6.0+dfsg-1+deb7u1DSA-3330-1
activemqsourcejessie5.6.0+dfsg1-4+deb8u1DSA-3330-1
activemqsource(unstable)5.6.0+dfsg1-4+deb8u1792857

Home - Debian Security - Source (Git)

OS impact

debian Debian Fixed 4 releases
VersionStatusFixed in
trixie Fixed 5.6.0+dfsg1-4+deb8u1
sid Fixed 5.6.0+dfsg1-4+deb8u1
bullseye Fixed 5.6.0+dfsg1-4+deb8u1
bookworm Fixed 5.6.0+dfsg1-4+deb8u1

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.apache.activemq:activemq-client<5.11.05.11.0

Application impact

VendorProductVersionsFixed
apache apacheactivemq{"endIncluding":"5.10.0"}
oracle oraclebusiness_intelligence_publisher12.2.1.0.0
oracle oraclefusion_middleware8.1
oracle oraclefusion_middleware9.0
oracle oraclefusion_middleware11.1.1.7.4
oracle oraclefusion_middleware12.1.3.0.0

References

CWEs

CWE-264

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.