Alerts This Week
Warning Icon 1 469
Alerts This Week
Warning Icon 1 469

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
197

Debian 9 DLA-2588-1 Critical: Zeromq3 Memory Leak And Heap Overflow

Two security issues have been detected in zeromq3. CVE-2021-20234 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2588-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Anton Gladky March 09, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : zeromq3 Version : 4.2.1-4+deb9u4 CVE ID : CVE-2021-20234 CVE-2021-20235 Two security issues have been detected in zeromq3. CVE-2021-20234 Memory leak in client induced by malicious server(s) without CURVE/ZAP. From issue description [1]. When a pipe processes a delimiter and is already not in active state but still has an unfinished message, the message is leaked. CVE-2021-20235 Heap overflow when receiving malformed ZMTP v1 packets. From issue description [2]. The static allocator was implemented to shrink its recorded size similarly to the shared allocator. But it does not need to, and it should not, because unlike the shared one the static allocator always uses a static buffer, with a size defined by the ZMQ_IN_BATCH_SIZE socket option (default 8192), so changing the size opens the library to heap overflows. The static allocator is used only with ZMTP v1 peers. [1] https://github.com/zeromq/libzmq/security/advisories/GHSA-wfr2-29gj-5w87 [2] https://github.com/zeromq/libzmq/security/advisories/GHSA-fc3w-qxf5-7hp6 For Debian 9 stretch, these problems have been fixed in version 4.2.1-4+deb9u4. We recommend that you upgrade your zeromq3 packages. For the detailed security status of zeromq3 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/zeromq3 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Patchreleased for zeromq3 tackling severe memory leak and heap overflow vulnerabilities identified in CVE-2021-20234 and CVE-2021-20235.. Zeromq3 Security, Debian Update, Memory Leak, Heap Overflow, Critical Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 10, 2021 Critical Debian LTS
87

Debian: DSA-4761-1 Critical Update: ZeroMQ3 Denial of Service Threat

It was discovered that ZeroMQ, a lightweight messaging kernel library does not properly handle connecting peers before a handshake is completed. A remote, unauthenticated client connecting to an application using the libzmq library, running with a socket listening with CURVE . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4761-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso September 07, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : zeromq3 CVE ID : CVE-2020-15166 It was discovered that ZeroMQ, a lightweight messaging kernel library does not properly handle connecting peers before a handshake is completed. A remote, unauthenticated client connecting to an application using the libzmq library, running with a socket listening with CURVE encryption/authentication enabled can take advantage of this flaw to cause a denial of service affecting authenticated and encrypted clients. For the stable distribution (buster), this problem has been fixed in version 4.3.1-4+deb10u2. We recommend that you upgrade your zeromq3 packages. For the detailed security status of zeromq3 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/zeromq3 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian security announcement DSA-4761-1 addresses a resolution for a ZeroMQ service disruption flaw.. Debian Security, ZeroMQ, Remote Attack, Messaging Library, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 07, 2020 Critical Debian
87

Debian: DSA-3255-1 Critical: Zeromq3 Protocol Downgrade Attack

It was discovered that libzmq, a lightweight messaging kernel, is susceptible to a protocol downgrade attack on sockets using the ZMTP v3 protocol. This could allow remote attackers to bypass ZMTP v3 security mechanisms by sending ZMTP v2 or earlier headers. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3255-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Alessandro Ghedini May 10, 2015 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : zeromq3 CVE ID : none assigned yet Debian Bug : 784366 It was discovered that libzmq, a lightweight messaging kernel, is susceptible to a protocol downgrade attack on sockets using the ZMTP v3 protocol. This could allow remote attackers to bypass ZMTP v3 security mechanisms by sending ZMTP v2 or earlier headers. For the stable distribution (jessie), this problem has been fixed in version 4.0.5+dfsg-2+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 4.0.5+dfsg-3. For the unstable distribution (sid), this problem has been fixed in version 4.0.5+dfsg-3. We recommend that you upgrade your zeromq3 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian has released a critical security update for zeromq3 to mitigate protocol downgrade vulnerabilities that could potentially grant unauthorized remote access.. zeromq3 Security, Debian Update, Protocol Bypass, Messaging Kernel. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 10, 2015 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here