Rabbitmq-c Project Rabbitmq-c 0.2

CPE Details

Rabbitmq-c Project Rabbitmq-c 0.2
0.2
2023-06-23
11h32 +00:00
2023-06-23
14h05 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:rabbitmq-c_project:rabbitmq-c:0.2:*:*:*:*:*:*:*

Informations

Vendor

rabbitmq-c_project

Product

rabbitmq-c

Version

0.2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-35789 2023-06-15 22h00 +00:00 An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command line (e.g., for amqp-publish or amqp-consume) and are thus visible to local attackers by listing a process and its arguments.
5.5
Medium
CVE-2019-18609 2019-12-01 20h50 +00:00 An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header that leads to a smaller target_size value than needed. This condition is then carried on to a memcpy function that copies too much data into a heap buffer.
9.8
Critical