Lucene search

K
freebsdFreeBSD10A6D0AA-0B1C-11E5-BB90-002590263BF5
HistoryDec 04, 2014 - 12:00 a.m.

libzmq4 -- V3 protocol handler vulnerable to downgrade attacks

2014-12-0400:00:00
vuxml.freebsd.org
14

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.005

Percentile

75.6%

Pieter Hintjens reports:

It is easy to bypass the security mechanism in 4.1.0 and 4.0.5 by
sending a ZMTP v2 or earlier header. The library accepts such
connections without applying its security mechanism.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchlibzmq4= 4.0.0UNKNOWN
FreeBSDanynoarchlibzmq4< 4.0.6UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.005

Percentile

75.6%