Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
RabbitMQ is an implementation of AMQP, the emerging standard for high
performance enterprise messaging. The RabbitMQ server is a robust and
scalable implementation of an AMQP broker.
Security Fix(es):
* A resource-consumption flaw was found in RabbitMQ Server, where the
lengths_age or lengths_incr parameters were not validated in the management
plugin. Remote, authenticated users with certain privileges could exploit
this flaw to cause a denial of service by passing values which were too
large. (CVE-2015-8786)
https://access.redhat.com/security/cve/CVE-2015-8786 https://access.redhat.com/security/updates/classification/#moderate
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7:
Source:
rabbitmq-server-3.3.5-31.el7ost.src.rpm
noarch:
rabbitmq-server-3.3.5-31.el7ost.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
An update for rabbitmq-server is now available for Red Hat Enterprise LinuxOpenStack Platform 7.0 (Kilo) for RHEL 7.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 - noarch
1404150 - CVE-2015-8786 rabbitmq-server: DoS via lengths_age or lengths_incr parameter in the management plugin
1405211 - RabbitMQ logs are not rotated properly
Get the latest Linux and open source security news straight to your inbox.