CVE-2019-13132: Buffer Overflow
In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled, may cause a stack overflow and overwrite the stack with arbitrary data, due to a buffer overflow in the library. Users running public servers with the above configuration are highly encouraged to upgrade as soon as possible, as there are no known mitigations.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-13132?
CVE-2019-13132 is a vulnerability in ZeroMQ libzmq versions before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2.
How severe is CVE-2019-13132?
CVE-2019-13132 has a severity rating of 9.8 (Critical).
What is the impact of CVE-2019-13132?
CVE-2019-13132 could allow a remote, unauthenticated client to cause a stack overflow and overwrite the stack with arbitrary data.
Which software versions are affected by CVE-2019-13132?
ZeroMQ libzmq versions before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2 are affected.
How can I fix CVE-2019-13132?
To fix CVE-2019-13132, it is recommended to update ZeroMQ libzmq to version 4.3.2 or later.