First published: Wed Jun 03 2015(Updated: )
libzmq before 4.0.6 and 4.1.x before 4.1.1 allows remote attackers to conduct downgrade attacks and bypass ZMTP v3 protocol security mechanisms via a ZMTP v2 or earlier header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZeroMQ | <=4.0.5 | |
ZeroMQ | =4.1.0-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9721 has been classified as a moderate severity vulnerability.
To fix CVE-2014-9721, upgrade ZeroMQ to version 4.0.6 or 4.1.1 or later.
CVE-2014-9721 allows remote attackers to conduct downgrade attacks against the ZMTP v3 protocol.
CVE-2014-9721 affects ZeroMQ versions before 4.0.6 and the 4.1.0-rc1 version.
CVE-2014-9721 allows bypassing the security mechanisms of the ZMTP v3 protocol.