UBUNTU-CVE-2016-9877

Source
https://ubuntu.com/security/CVE-2016-9877
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2016/UBUNTU-CVE-2016-9877.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2016-9877
Related
Published
2016-12-29T00:00:00Z
Modified
2025-01-13T10:21:17Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection request. Connections that use TLS with a client-provided certificate are not affected.

References

Affected packages

Ubuntu:14.04:LTS / rabbitmq-server

Package

Name
rabbitmq-server
Purl
pkg:deb/ubuntu/rabbitmq-server@3.2.4-1ubuntu0.1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.2.4-1ubuntu0.1

Affected versions

3.*

3.1.3-1
3.1.5-1
3.2.0-1
3.2.1-1
3.2.2-1
3.2.3-1
3.2.4-1

Ecosystem specific

{
    "ubuntu_priority": "high",
    "binaries": [
        {
            "binary_version": "3.2.4-1ubuntu0.1",
            "binary_name": "rabbitmq-server"
        }
    ],
    "availability": "No subscription required"
}

Ubuntu:16.04:LTS / rabbitmq-server

Package

Name
rabbitmq-server
Purl
pkg:deb/ubuntu/rabbitmq-server@3.5.7-1ubuntu0.16.04.2?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.7-1ubuntu0.16.04.2

Affected versions

3.*

3.5.4-1
3.5.4-3
3.5.4-3.1
3.5.7-1
3.5.7-1ubuntu0.16.04.1

Ecosystem specific

{
    "ubuntu_priority": "high",
    "binaries": [
        {
            "binary_version": "3.5.7-1ubuntu0.16.04.2",
            "binary_name": "rabbitmq-server"
        }
    ],
    "availability": "No subscription required"
}