Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (crash) via a crafted message, which triggers an out-of-bounds read.
https://issues.apache.org/jira/browse/QPID-4629
https://bugzilla.redhat.com/show_bug.cgi?id=861241
http://svn.apache.org/viewvc?view=revision&revision=1453031
http://secunia.com/advisories/52516