Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia: 2019-0323 Critical: Zeromq Buffer Overflow Security Issue

mageia
Calendar Grey November 14, 2019
Dist Mageia Esm H88
Uncover the details of the MGASA-2019-0323 advisory concerning a security patch for zeromq addressing stack overflow weaknesses.
A security vulnerability has been reported in libzmq/zeromq

Summary

A security vulnerability has been reported in libzmq/zeromq.
a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled, may cause a stack overflow and overwrite the stack with arbitrary data, due to a buffer overflow in the library. Users running public serverswith the above configuration are highly encouraged to upgrade as soon as possible, as there are no known mitigations. All versions from 4.0.0 and upwards are affected (CVE-2019-13132).

References

- https://bugs.mageia.org/show_bug.cgi?id=25113

- https://www.openwall.com/lists/oss-security/2019/07/08/6

- https://lists.debian.org/debian-security-announce/2019/msg00125.html

- https://ubuntu.com/security/notices/USN-4050-1

- https://www.cve.org/CVERecord?id=CVE-2019-13132

Resolution

SRPMS

- 7/core/zeromq-4.3.2-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 14 Nov 2019
URL: https://advisories.mageia.org/MGASA-2019-0323.html
Type: security
CVE: CVE-2019-13132

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here