In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled, may cause a stack overflow and overwrite the stack with arbitrary data, due to a buffer overflow in the library. Users running public servers with the above configuration are highly encouraged to upgrade as soon as possible, as there are no known mitigations.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade zeromq | Nov 8, 2019 | Jul 10, 2019 |
| Debian | — | Upgrade zeromq3 | Jul 10, 2019 | Jul 10, 2019 |
| Freebsd | — | Upgrade libzmq4 | Nov 4, 2022 | May 25, 2021 |
| Gentoo Linux | — | Upgrade net-libs/zeromq. | Aug 16, 2019 | Jul 10, 2019 |
| Suse | — | Upgrade zeromq-develUpgrade libzmq5Upgrade libzmq3Upgrade zeromq-tools | Jul 9, 2019 | Jul 8, 2019 |
| Ubuntu | — | Upgrade libzmq5 (Ubuntu Pro)Upgrade libzmq3 (Ubuntu Pro)Upgrade libzmq5 | Jul 9, 2019 | Jul 8, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 10, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub