Joined: 12 May 2004
|Posted: Fri Mar 13, 2020 4:26 am Post subject: [ GLSA 202003-07 ] RabbitMQ C client
|Gentoo Linux Security Advisory
Title: RabbitMQ C client: Arbitrary code execution (GLSA 202003-07)
A vulnerability in RabbitMQ C client might allow an attacker to
execute arbitrary code.
A C-language AMQP client library for use with v2.0+ of the RabbitMQ
Vulnerable: < 0.10.0
Unaffected: >= 0.10.0
Architectures: All supported architectures
It was discovered that RabbitMQ C client incorrectly handled certain
A remote attacker, by sending a specially crafted request, could
possibly execute arbitrary code with the privileges of the process or
cause a Denial of Service condition.
There is no known workaround at this time.
All RabbitMQ C client users should upgrade to the latest version:
|# emerge --sync
# emerge --ask --oneshot --verbose ">=net-libs/rabbitmq-c-0.10.0"