← All CVEs

CVE-2019-13132

critical · 9.8

In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled, may cause a stack overflow and overwrite the stack with arbitrary data, due to a buffer overflow in the library. Users running public servers with the above configuration are highly encouraged to upgrade as soon as possible, as there are no known mitigations.

9.8
CVSS
41.6%
EPSS (exploit prob.)
99th
EPSS percentile
2019-07-10
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-787

Affected products

VendorProductAffected versions
zeromqlibzmq< 4.0.9
zeromqlibzmq>= 4.1.0, < 4.1.7
zeromqlibzmq>= 4.2.0, < 4.3.2
debiandebian_linux8.0
debiandebian_linux9.0
canonicalubuntu_linux16.04
canonicalubuntu_linux18.04
canonicalubuntu_linux18.10
canonicalubuntu_linux19.04
fedoraprojectfedora29
fedoraprojectfedora30
fedoraprojectfedora31

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-13132