Two security issues have been detected in zeromq3. CVE-2021-20234 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2588-1
It was discovered that ZeroMQ, a lightweight messaging kernel library does not properly handle connecting peers before a handshake is completed. A remote, unauthenticated client connecting to an application using the libzmq library, running with a socket listening with CURVE . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4761-1
It was discovered that libzmq, a lightweight messaging kernel, is susceptible to a protocol downgrade attack on sockets using the ZMTP v3 protocol. This could allow remote attackers to bypass ZMTP v3 security mechanisms by sending ZMTP v2 or earlier headers. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3255-1
Get the latest Linux and open source security news straight to your inbox.