PT-2020-6204 · Zeromq+4 · Zeromq+4
Bluca
·
Published
2020-09-07
·
Updated
2024-06-15
·
CVE-2020-15166
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ZeroMQ versions prior to 4.3.3
Description
The issue is related to an error in the resource control mechanism of ZeroMQ, a messaging system component. This allows a remote attacker to cause a denial-of-service. Users with TCP transport public endpoints, even with CURVE/ZAP enabled, are impacted. If a raw TCP socket is opened and connected to an endpoint that is fully configured with CURVE/ZAP, legitimate clients will not be able to exchange any messages. Handshakes complete successfully, and messages are delivered to the library, but the server application never receives them.
Recommendations
For ZeroMQ versions prior to 4.3.3, update to version 4.3.3 to resolve the issue. As a temporary workaround, consider restricting access to TCP transport public endpoints to minimize the risk of exploitation. Avoid using raw TCP sockets connected to endpoints fully configured with CURVE/ZAP until the issue is resolved.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Suse
Ubuntu
Zeromq