Lucene search

K
cvelistRedhatCVELIST:CVE-2021-20237
HistoryMay 28, 2021 - 10:42 a.m.

CVE-2021-20237

2021-05-2810:42:23
CWE-400
redhat
www.cve.org
2

8.6 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

64.8%

An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ’s src/xpub.cpp in versions before 4.3.3. This flaw allows a remote unauthenticated attacker to send crafted PUB messages that consume excessive memory if the CURVE/ZAP authentication is disabled on the server, causing a denial of service. The highest threat from this vulnerability is to system availability.

CNA Affected

[
  {
    "product": "zeromq",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "zeromq 4.3.3"
      }
    ]
  }
]

8.6 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

64.8%