USN-5004-1: RabbitMQ vulnerabilities
24 June 2021
Several security issues were fixed in rabbitmq-server.
Releases
Packages
- rabbitmq-server - AMQP server written in Erlang
Details
It was discovered that RabbitMQ incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2019-11287)
Jonathan Knudsen discovered RabbitMQ incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2021-22116)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 21.04
Ubuntu 20.10
Ubuntu 20.04
Ubuntu 18.04
Ubuntu 16.04
-
rabbitmq-server
-
3.5.7-1ubuntu0.16.04.4+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.