{ "dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": { "state": "PUBLISHED", "cveId": "CVE-2019-13132", "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "assignerShortName": "mitre", "dateUpdated": "2024-08-04T23:41:10.464Z", "dateReserved": "2019-07-01T00:00:00.000Z", "datePublished": "2019-07-10T00:00:00.000Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "shortName": "mitre", "dateUpdated": "2024-04-11T21:35:49.955Z" }, "descriptions": [ { "lang": "en", "value": "In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled, may cause a stack overflow and overwrite the stack with arbitrary data, due to a buffer overflow in the library. Users running public servers with the above configuration are highly encouraged to upgrade as soon as possible, as there are no known mitigations." } ], "affected": [ { "vendor": "n/a", "product": "n/a", "versions": [ { "version": "n/a", "status": "affected" } ] } ], "references": [ { "name": "[oss-security] 20190708 CVE-2019-13132: zeromq/libzmq: denial of service via stack overflow with arbitrary data", "tags": [ "mailing-list" ], "url": "http://www.openwall.com/lists/oss-security/2019/07/08/6" }, { "name": "[debian-lts-announce] 20190708 [SECURITY] [DLA 1849-1] zeromq3 security update", "tags": [ "mailing-list" ], "url": "https://lists.debian.org/debian-lts-announce/2019/07/msg00007.html" }, { "name": "USN-4050-1", "tags": [ "vendor-advisory" ], "url": "https://usn.ubuntu.com/4050-1/" }, { "name": "DSA-4477", "tags": [ "vendor-advisory" ], "url": "https://www.debian.org/security/2019/dsa-4477" }, { "name": "20190709 [SECURITY] [DSA 4477-1] zeromq3 security update", "tags": [ "mailing-list" ], "url": "https://seclists.org/bugtraq/2019/Jul/13" }, { "url": "https://github.com/zeromq/libzmq/issues/3558" }, { "url": "https://github.com/zeromq/libzmq/releases" }, { "name": "109284", "tags": [ "vdb-entry" ], "url": "http://www.securityfocus.com/bid/109284" }, { "name": "openSUSE-SU-2019:1767", "tags": [ "vendor-advisory" ], "url": "http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00033.html" }, { "name": "GLSA-201908-17", "tags": [ "vendor-advisory" ], "url": "https://security.gentoo.org/glsa/201908-17" }, { "name": "FEDORA-2019-d20ce4d5a1", "tags": [ "vendor-advisory" ], "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AVCTNUEOFFZUNJOXFCYCF3C6Y6NDILI3/" }, { "name": "FEDORA-2019-8916b4e890", "tags": [ "vendor-advisory" ], "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T6HINI24SL7CU6XIJWUOSGTZWEFOOL7X/" }, { "name": "FEDORA-2019-4d8f9a9235", "tags": [ "vendor-advisory" ], "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MK7SJYDJ7MMRRRPCUN3SCSE7YK6ZSHVS/" }, { "url": "https://fangpenlin.com/posts/2024/04/07/how-i-discovered-a-9-point-8-critical-security-vulnerability-in-zeromq-with-mostly-pure-luck/" }, { "url": "https://news.ycombinator.com/item?id=39970716" } ], "problemTypes": [ { "descriptions": [ { "type": "text", "lang": "en", "description": "n/a" } ] } ], "datePublic": "2019-07-08T00:00:00.000Z" }, "adp": [ { "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-04T23:41:10.464Z" }, "title": "CVE Program Container", "references": [ { "name": "[oss-security] 20190708 CVE-2019-13132: zeromq/libzmq: denial of service via stack overflow with arbitrary data", "tags": [ "mailing-list", "x_transferred" ], "url": "http://www.openwall.com/lists/oss-security/2019/07/08/6" }, { "name": "[debian-lts-announce] 20190708 [SECURITY] [DLA 1849-1] zeromq3 security update", "tags": [ "mailing-list", "x_transferred" ], "url": "https://lists.debian.org/debian-lts-announce/2019/07/msg00007.html" }, { "name": "USN-4050-1", "tags": [ "vendor-advisory", "x_transferred" ], "url": "https://usn.ubuntu.com/4050-1/" }, { "name": "DSA-4477", "tags": [ "vendor-advisory", "x_transferred" ], "url": "https://www.debian.org/security/2019/dsa-4477" }, { "name": "20190709 [SECURITY] [DSA 4477-1] zeromq3 security update", "tags": [ "mailing-list", "x_transferred" ], "url": "https://seclists.org/bugtraq/2019/Jul/13" }, { "url": "https://github.com/zeromq/libzmq/issues/3558", "tags": [ "x_transferred" ] }, { "url": "https://github.com/zeromq/libzmq/releases", "tags": [ "x_transferred" ] }, { "name": "109284", "tags": [ "vdb-entry", "x_transferred" ], "url": "http://www.securityfocus.com/bid/109284" }, { "name": "openSUSE-SU-2019:1767", "tags": [ "vendor-advisory", "x_transferred" ], "url": "http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00033.html" }, { "name": "GLSA-201908-17", "tags": [ "vendor-advisory", "x_transferred" ], "url": "https://security.gentoo.org/glsa/201908-17" }, { "name": "FEDORA-2019-d20ce4d5a1", "tags": [ "vendor-advisory", "x_transferred" ], "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AVCTNUEOFFZUNJOXFCYCF3C6Y6NDILI3/" }, { "name": "FEDORA-2019-8916b4e890", "tags": [ "vendor-advisory", "x_transferred" ], "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T6HINI24SL7CU6XIJWUOSGTZWEFOOL7X/" }, { "name": "FEDORA-2019-4d8f9a9235", "tags": [ "vendor-advisory", "x_transferred" ], "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MK7SJYDJ7MMRRRPCUN3SCSE7YK6ZSHVS/" }, { "url": "https://fangpenlin.com/posts/2024/04/07/how-i-discovered-a-9-point-8-critical-security-vulnerability-in-zeromq-with-mostly-pure-luck/", "tags": [ "x_transferred" ] }, { "url": "https://news.ycombinator.com/item?id=39970716", "tags": [ "x_transferred" ] } ] } ] } }