Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <CAPVVMa_M_c8_kTWep-19+kTDZ6Www-JwqHn5SYhkgvcFvDoFEA@mail.gmail.com>
Date: Tue, 24 May 2016 06:09:35 -0600
From: Tim Bain <tbain@...mni.duke.edu>
To: ActiveMQ Users <users@...ivemq.apache.org>
Cc: dev@...ivemq.apache.org, 
	Apache Security Response Team <security@...che.org>, bugtraq@...urityfocus.com, 
	oss-security@...ts.openwall.com
Subject: Re: [ANNOUNCE] CVE-2016-3088: ActiveMQ Fileserver web application vulnerabilities

Does the range of versions specified mean that the issue is already
addressed in 5.13.3, or was its omission from the range an oversight?

Tim
On May 24, 2016 2:41 AM, "Dejan Bosanac" <dejan@...httale.net> wrote:

> There's a security vulnerability reported against Apache
> ActiveMQ 5.13.2 and older versions.
>
> Please check the following document and see if you’re affected by the
> issue.
>
>
> http://activemq.apache.org/security-advisories.data/CVE-2016-3088-announcement.txt
>
> Vulnerability is similar to the one reported in CVE-2015-1830 (
>
> http://activemq.apache.org/security-advisories.data/CVE-2015-1830-announcement.txt
> ).
> The fileserver web application will be removed in 5.14.0 release and users
> are advised not to use it and disable it in older versions.
>
> Regards
> --
> Dejan Bosanac
> about.me/dejanb
>

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.