CVE-2021-20236
published 2021-05-28CVE-2021-20236: A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by sending…
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.60%
73.1th percentile
A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscription requests and then unsubscribing. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zeromq3 | < zeromq3 4.3.3-1 (bookworm) | zeromq3 4.3.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | cm1_zeromq_4.3.4-1_on_cbl_mariner_1.0 | — | — |
| redhat | ceph_storage | — | — |
| redhat | enterprise_linux | — | — |
| zeromq | zeromq | < 4.3.3 | 4.3.3 |
| zeromq | zeromq | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscription requests and th
vendor_msrc·2021-05-11·CVSS 9.8
CVE-2021-20236 [CRITICAL] CWE-787 A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscription requests and th
A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscription requests and then unsubscribing. The highest threat from this vulnerability is to confidentiality integrity as well as system availability.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX
Debian
CVE-2021-20236: zeromq3 - A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows...
vendor_debian·2021·CVSS 9.8
CVE-2021-20236 [CRITICAL] CVE-2021-20236: zeromq3 - A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows...
A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscription requests and then unsubscribing. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Scope: local
bookworm: resolved (fixed in 4.3.3-1)
bullseye: resolved (fixed in 4.3.3-1)
forky: resolved (fixed in 4.3.3-1)
sid: resolved (fixed in 4.3.3-1)
trixie: resolved (fixed in 4.3.3-1)
Red Hat
zeromq: Stack overflow on server running PUB/XPUB socket
vendor_redhat·2020-09-07·CVSS 9.8
CVE-2021-20236 [CRITICAL] CWE-120 zeromq: Stack overflow on server running PUB/XPUB socket
zeromq: Stack overflow on server running PUB/XPUB socket
A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscription requests and then unsubscribing. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
A flaw was found in the ZeroMQ server. This flaw allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscription requests and then unsubscribing. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Package: zeromq3 (Red Hat Ceph Storage 2) - Out of support scope
GHSA
GHSA-4j25-p3vq-p264: A flaw was found in the ZeroMQ server in versions before 4
ghsa_unreviewed·2022-05-24
CVE-2021-20236 [CRITICAL] CWE-787 GHSA-4j25-p3vq-p264: A flaw was found in the ZeroMQ server in versions before 4
A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscription requests and then unsubscribing. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
OSV
CVE-2021-20236: A flaw was found in the ZeroMQ server in versions before 4
osv·2021-05-28·CVSS 9.8
CVE-2021-20236 [CRITICAL] CVE-2021-20236: A flaw was found in the ZeroMQ server in versions before 4
A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscription requests and then unsubscribing. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-05-28
Published