Candidate: CVE-2015-8786 PublicDate: 2016-12-09 20:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8786 http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html https://github.com/rabbitmq/rabbitmq-server/releases/tag/rabbitmq_v3_6_1 Description: The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter. Ubuntu-Description: Notes: Bugs: https://github.com/rabbitmq/rabbitmq-management/issues/97 Priority: negligible Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_rabbitmq-server: upstream_rabbitmq-server: needs-triage precise_rabbitmq-server: not-affected precise/esm_rabbitmq-server: DNE (precise was not-affected) trusty_rabbitmq-server: ignored (reached end-of-life) trusty/esm_rabbitmq-server: DNE (trusty was needed) vivid/stable-phone-overlay_rabbitmq-server: DNE vivid/ubuntu-core_rabbitmq-server: DNE xenial_rabbitmq-server: ignored (end of standard support, was needed) esm-infra/xenial_rabbitmq-server: needed yakkety_rabbitmq-server: ignored (reached end-of-life) zesty_rabbitmq-server: not-affected (3.6.6-1) artful_rabbitmq-server: not-affected (3.6.6-1) bionic_rabbitmq-server: not-affected (3.6.6-1) cosmic_rabbitmq-server: not-affected (3.6.6-1) disco_rabbitmq-server: not-affected (3.6.6-1) eoan_rabbitmq-server: not-affected (3.6.6-1) focal_rabbitmq-server: not-affected (3.6.6-1) groovy_rabbitmq-server: not-affected (3.6.6-1) hirsute_rabbitmq-server: not-affected (3.6.6-1) impish_rabbitmq-server: not-affected (3.6.6-1) jammy_rabbitmq-server: not-affected (3.6.6-1) devel_rabbitmq-server: not-affected (3.6.6-1)