PT-2021-8015 · Zeromq+3 · Zeromq+3

·

CVE-2021-20236

·

Published

2021-05-28

·

Updated

2024-04-03

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ZeroMQ versions prior to 4.3.3
Description A flaw in the ZeroMQ server allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscription requests and then unsubscribing. This poses a threat to confidentiality, integrity, and system availability.
Recommendations For versions prior to 4.3.3, update to version 4.3.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the ZeroMQ server or disabling the topic subscription feature until a patch is applied. Avoid using crafted topic subscription requests to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1314
BDU:2024-02576
CVE-2021-20236
GHSA-QQ65-X72M-9WR8

Affected Products

Alt Linux
Astra Linux
Red Os
Zeromq