Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Fedora 23: 2016-4567 High: OpenSSL Vulnerability in TLS Protocol

fedora
Calendar Grey May 30, 2015
Scroller Fedora
A crucial patch fortifies security for ZeroMQ in Fedora 22, preventing downgrade attacks by validating protocols against standards and ensuring secure communication.
Cherry-pick a fix for the protocol downgrade attack (CVE-2014-9721)

Summary

The 0MQ lightweight messaging kernel is a library which extends the

standard socket interfaces with features traditionally provided by

specialized messaging middle-ware products. 0MQ sockets provide an

abstraction of asynchronous message queues, multiple messaging

patterns, message filtering (subscriptions), seamless access to

multiple transport protocols and more.

This package contains the ZeroMQ shared library.

Update Information:

Cherry-pick a fix for the protocol downgrade attack (CVE-2014-9721)

Change Log

* Tue May 19 2015 Thomas Spura - 4.0.5-3 - Cherry-pick patch for protocol downgrade attack (#1221666) - Remove Provides:zeromq-utils - Remove %defattr * Sat May 2 2015 Kalev Lember - 4.0.5-2 - Rebuilt for GCC 5 C++11 ABI change

References


[ 1 ] Bug #1221666 - CVE-2014-9721 zeromq: protocol downgrade attack on sockets using the ZMTP v3 protocol https://bugzilla.redhat.com/show_bug.cgi?id=1221666

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update zeromq' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
important
Lowest
Low
Medium
High
Critical

Name: zeromq
Product: Fedora 22
Version: 4.0.5
Release: 3.fc22
Summary: Software library for fast, message-based applications

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.