UBUNTU-CVE-2012-4446

Source
https://ubuntu.com/security/CVE-2012-4446
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-4446.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2012-4446
Upstream
  • CVE-2012-4446
Published
2013-03-14T03:10:00Z
Modified
2025-10-24T04:44:57Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.

References

Affected packages

Ubuntu:16.04:LTS / qpid-cpp

Package

Name
qpid-cpp
Purl
pkg:deb/ubuntu/qpid-cpp@0.16-9ubuntu2?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.16-9build1
0.16-9ubuntu1
0.16-9ubuntu2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libqmf-dev"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libqmf1"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libqmf2-1"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libqmf2-dev"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libqmfconsole2"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libqmfconsole2-dev"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libqmfengine1"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libqmfengine1-dev"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libqpid-perl"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libqpid-ruby1.8"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libqpidbroker2"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libqpidbroker2-dev"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libqpidclient2"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libqpidclient2-dev"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libqpidcommon2"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libqpidcommon2-dev"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libqpidmessaging2"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libqpidmessaging2-dev"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libqpidtypes1"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libqpidtypes1-dev"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "librdmawrap2"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "librdmawrap2-dev"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libsslcommon2"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "libsslcommon2-dev"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "python-cqmf2"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "python-cqpid"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "python-qmf"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "python-qmf2"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "qmfgen"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "qpid-client"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "qpidd"
        },
        {
            "binary_version": "0.16-9ubuntu2",
            "binary_name": "ruby-qpid"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-4446.json"