A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1. A v2_decoder.cpp zmq::v2_decoder_t::size_ready integer overflow allows an authenticated attacker to overwrite an arbitrary amount of bytes beyond the bounds of a buffer, which can be leveraged to run arbitrary code on the target system. The memory layout allows the attacker to inject OS commands into a data structure located immediately after the problematic buffer (i.e., it is not necessary to use a typical buffer-overflow exploitation technique that changes the flow of control).
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade zeromq | Feb 15, 2019 | Jan 13, 2019 |
| Debian | — | Upgrade zeromq3 | Jan 16, 2019 | Jan 13, 2019 |
| Freebsd | — | Upgrade libzmq4 | Jan 27, 2019 | Jan 26, 2019 |
| Gentoo Linux | — | Upgrade net-libs/zeromq. | Mar 29, 2019 | Jan 13, 2019 |
| Suse | — | Upgrade zeromq-toolsUpgrade zeromq-develUpgrade libzmq5 | Jan 19, 2019 | Jan 13, 2019 |
| Ubuntu | — | Upgrade zeromq3 | Nov 19, 2024 | Jan 13, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 13, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub