PT-2019-3412 · Zeromq+4 · Libzmq+4

Fang-Pen Lin

·

Published

2019-06-20

·

Updated

2024-06-15

·

CVE-2019-13132

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ZeroMQ libzmq versions 4.0.0 through 4.0.8 ZeroMQ libzmq versions 4.1.x through 4.1.6 ZeroMQ libzmq versions 4.2.x through 4.3.1
Description The issue is related to a buffer overflow in the ZeroMQ libzmq library, which can cause a stack overflow and allow an attacker to overwrite the stack with arbitrary data. This can lead to unauthorized access to sensitive information, disruption of data integrity, and denial of service. The vulnerability can be exploited by a remote, unauthenticated client connecting to a libzmq application with CURVE encryption/authentication enabled.
Recommendations For ZeroMQ libzmq versions 4.0.0 through 4.0.8, upgrade to version 4.0.9 or later. For ZeroMQ libzmq versions 4.1.x through 4.1.6, upgrade to version 4.1.7 or later. For ZeroMQ libzmq versions 4.2.x through 4.3.1, upgrade to version 4.3.2 or later. As a temporary workaround, consider disabling CURVE encryption/authentication until a patch is available. Restrict access to public servers with the vulnerable configuration to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1314
BDU:2019-03566
BDU:2019-03576
CVE-2019-13132
DLA-1849-1
DSA-4477-1
MGASA-2019-0323
OPENSUSE-SU-2019:1767-1
OPENSUSE-SU-2019_1767-1
OPENSUSE-SU-2024:11540-1
SUSE-FU-2022:0444-1
SUSE-FU-2022:0445-1
SUSE-SU-2019:14117-1
SUSE-SU-2019:1776-1
SUSE-SU-2019:1785-1
SUSE-SU-2019_14117-1
SUSE-SU-2019_1776-1
SUSE-SU-2019_1785-1
USN-4050-1
USN-4920-1

Affected Products

Alt Linux
Linuxmint
Suse
Ubuntu
Libzmq