ZeroHour

CVE-2021-20236

CVSS 3.1
9.8 critical
EPSS
2%p74
Published
()
Modified
Description

A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscription requests and then unsubscribing. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Vendors
zeromqredhatfedoraproject
Products
zeromq, ceph storage, enterprise linux, fedora
Weakness
CWE-120, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.