Zeromq · Libzmq · CVE-2014-9721
**Name of the Vulnerable Software and Affected Versions**
libzmq versions prior to 4.0.6
libzmq versions 4.1.x prior to 4.1.1
**Description**
The issue allows remote attackers to conduct downgrade attacks, bypassing security mechanisms of the ZMTP v3 protocol by using a ZMTP v2 or earlier header.
**Recommendations**
For libzmq versions prior to 4.0.6, update to version 4.0.6 or later.
For libzmq versions 4.1.x prior to 4.1.1, update to version 4.1.1 or later.