PT-2020-6204 · Zeromq+4 · Zeromq+4

Bluca

·

Published

2020-09-07

·

Updated

2024-06-15

·

CVE-2020-15166

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ZeroMQ versions prior to 4.3.3
Description The issue is related to an error in the resource control mechanism of ZeroMQ, a messaging system component. This allows a remote attacker to cause a denial-of-service. Users with TCP transport public endpoints, even with CURVE/ZAP enabled, are impacted. If a raw TCP socket is opened and connected to an endpoint that is fully configured with CURVE/ZAP, legitimate clients will not be able to exchange any messages. Handshakes complete successfully, and messages are delivered to the library, but the server application never receives them.
Recommendations For ZeroMQ versions prior to 4.3.3, update to version 4.3.3 to resolve the issue. As a temporary workaround, consider restricting access to TCP transport public endpoints to minimize the risk of exploitation. Avoid using raw TCP sockets connected to endpoints fully configured with CURVE/ZAP until the issue is resolved.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1314
BDU:2021-03549
CVE-2020-15166
DLA-2443-1
DSA-4761-1
GHSA-25WP-CF8G-938M
MGASA-2020-0367
OESA-2024-1133
OPENSUSE-SU-2020:1907-1
OPENSUSE-SU-2020:1910-1
OPENSUSE-SU-2020_1907-1
OPENSUSE-SU-2020_1910-1
OPENSUSE-SU-2024:11540-1
SUSE-FU-2022:0444-1
SUSE-FU-2022:0445-1
SUSE-SU-2020:3264-1
SUSE-SU-2020_3264-1
USN-4920-1

Affected Products

Alt Linux
Linuxmint
Suse
Ubuntu
Zeromq