PT-2021-8015 · Zeromq+3 · Zeromq+3
Pedro Sampaio
·
Published
2021-05-28
·
Updated
2024-04-03
·
CVE-2021-20236
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ZeroMQ versions prior to 4.3.3
Description
A flaw in the ZeroMQ server allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscription requests and then unsubscribing. This poses a threat to confidentiality, integrity, and system availability.
Recommendations
For versions prior to 4.3.3, update to version 4.3.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the ZeroMQ server or disabling the topic subscription feature until a patch is applied. Avoid using crafted topic subscription requests to minimize the risk of exploitation.
Fix
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Red Os
Zeromq