Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Debian 9 Stretch DLA-2583-1 Critical: ActiveMQ Threats and Updates

debian lts
Calendar Grey March 5, 2021
Dist Debian Esm H88
Enhance your ActiveMQ installations to resolve various security vulnerabilities highlighted in the recent Debian LTS notice DLA-2583-1.
Multiple security issues were discovered in activemq, a message broker built around Java Message Service

Summary

CVE-2017-15709

When using the OpenWire protocol in activemq, it was found that
certain system details (such as the OS and kernel version) are
exposed as plain text.

CVE-2018-11775

TLS hostname verification when using the Apache ActiveMQ Client
was missing which could make the client vulnerable to a MITM
attack between a Java application using the ActiveMQ client and
the ActiveMQ server. This is now enabled by default.

CVE-2019-0222

Unmarshalling corrupt MQTT frame can lead to broker Out of Memory
exception making it unresponsive

CVE-2021-26117

The optional ActiveMQ LDAP login module can be configured to use
anonymous access to the LDAP server. The anonymous context is used
to verify a valid users password in error, resulting in no check
on the password.

For Debian 9 stretch, these problems have been fixed in version
5.14.3-3+deb9u2.

We recommend that you upgrade your activemq packages.

For the detailed security status of activemq please refer to

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: activemq
Version: 5.14.3-3+deb9u2
CVE ID: CVE-2017-15709 CVE-2018-11775 CVE-2019-0222
Debian Bug: 890352 908950 982590

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here