Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.
ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes the broker to exhaust all its memory in the SSL engine leading to DoS.
Note: TLS versions before TLSv1.3 (such as TLSv1.2) are broken but are not vulnerable to OOM. Previous TLS versions require a full handshake renegotiation which causes a connection to hang but not OOM. This is fixed as well.
This issue affects Apache ActiveMQ Client: before 5.19.4, from 6.0.0 before 6.2.4; Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.4; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.4.
Users are recommended to upgrade to version 6.2.4 or 5.19.5, which fixes the issue.
The coming days will be some of the most important and busiest moments for @inter_link.Here are several keyupdates that willbe announced
The release of Version 4.0.5the final updateof the 4.x series
Announcement of theBoard Members ofthe InterLink Foundation
#InterLink#ITLG#ITL
The coming days will be some of the most important and busiest moments for @inter_link. Here are several key updates that will be announced:
• The release of Version 4.0.5, the final update of the 4.x series
• Announcement of the Board Members of the InterLink Foundation
• Release of the InterLink Foundation Whitepaper and the 5-year strategic vision
• Launch of Version 5.0
• Launch of the InterLink Testnet
• Launch of the InterLink Private Mainnet
• Launch of the Transaction-Backed Digital Assets Protocol
The entire team is working 24/7 day and night to ensure everything proceeds smoothly.
The ship is ready. It’s time to set sail.
🇮🇷 #KeyUpdates
Brigadier General Ahmad Vahidi has assumed command of the Islamic Revolutionary Guard Corps (IRGC);
Muqtada al-Sadr declared three days of mourning in 🇮🇶 Iraq;
Large-scale rallies in 🇮🇷 Tehran and several other cities in support of the country’s leadership and armed forces;
Mass demonstrations in 🇮🇶 Baghdad, Basra, and other Iraqi cities;
Public rallies in support of Iran reported in 🇱🇧 Lebanon and 🇮🇳 Kashmir;
Launches of long-range Iranian missiles продолжаются;
Secretary of Iran’s Supreme National Security Council Ali Larijani stated that the armed forces are determined to continue resistance and warned that U.S. bases used for attacks will be considered legitimate targets;
Speaker of Parliament Mohammad Bagher Ghalibaf said Iran will not allow encroachment on its sovereignty and unity;
The death of Major General Abdolrahim Mousavi, Chief of the General Staff of Iran’s Armed Forces, has been confirmed;
The death of Iran’s Defense Minister, Major General Nasirzadeh, has been confirmed;
Air-raid sirens sounding in northern and central 🇮🇱 Israel, in settlements in the West Bank, and near the Dead Sea;
According to Fars News Agency, U.S. vessels will no longer be allowed to enter the Persian Gulf.
#Iran#Iraq#Israel#MiddleEast 🌍
Want to build a resilient VASP? Start by mastering your Business Risk Assessment.
For #VASPs, “business-risk” isn’t just a compliance phrase, it is the difference between scaling smoothly and running into unavoidable surprises.
🌏 amluae.com/regulator-ready-b…#AMLUAE#KeyUpdates
A little breakdown on @BioProtocol S2.
With @BioProtocol S2 around the corner,
Some keyupdates were made to transform @BioProtocol from a curated launchpad into a scalable, selfsustaining factory for DeSci where scientific innovation,funding, and discovery all happen onchain.👇🏾
Insights on the Alaska meeting! This call solidifies India's crucial global standing and active participation. It's a clear nod to the enduring India-Russia friendship, showing that India's loyalty is well understood and reciprocated. We never back down for our friends! #India#Russia#GlobalLeadership#FriendshipGoals#KeyUpdates