what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Debian Security Advisory 4761-1

Debian Security Advisory 4761-1
Posted Sep 28, 2020
Authored by Debian | Site debian.org

Debian Linux Security Advisory 4761-1 - It was discovered that ZeroMQ, a lightweight messaging kernel library does not properly handle connecting peers before a handshake is completed. A remote, unauthenticated client connecting to an application using the libzmq library, running with a socket listening with CURVE encryption/authentication enabled can take advantage of this flaw to cause a denial of service affecting authenticated and encrypted clients.

tags | advisory, remote, denial of service, kernel
systems | linux, debian
advisories | CVE-2020-15166
SHA-256 | 0b04a5aaab9ee659966e2bbeb22a5b3b23c2f888e4a32faf559460daca53aaa1

Debian Security Advisory 4761-1

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4761-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
September 07, 2020 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : zeromq3
CVE ID : CVE-2020-15166

It was discovered that ZeroMQ, a lightweight messaging kernel library
does not properly handle connecting peers before a handshake is
completed. A remote, unauthenticated client connecting to an application
using the libzmq library, running with a socket listening with CURVE
encryption/authentication enabled can take advantage of this flaw to
cause a denial of service affecting authenticated and encrypted clients.

For the stable distribution (buster), this problem has been fixed in
version 4.3.1-4+deb10u2.

We recommend that you upgrade your zeromq3 packages.

For the detailed security status of zeromq3 please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/zeromq3

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl9WhZhfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0QIXhAAgMLUYJtrZuZ/Bqv/75erF0MhlkK2VXVDpDM/dsWMZDXVPJXIHv+arptD
vMubLTIto3HuQwQHMp0hrBN0ztVaI9jdMNUnhhhxD+V5vGbOI7x4SLFMaAM7+1aa
6LphHDZeWKE17V5vD6eROHVDRLwm/PJ+ITRasrPTSQNzgcVszsBaOAGtbIKyt1SS
wB1OR8Zi+JR9xvFlMA1viSLIXaHHSSKSUm8Ozd+VKeShg3HE2PVgSqlWAZFwM+Z2
wLfypxZj0EywW+cid2VKepqvQ18402AolvPG4DFj5cGvHVc4ZNqmkFBOIFkda/nM
b83BmMAZeZgvjEgLcOEMxp7Jupt2GxDgyRR06+3e/oQSUZSzP4ge5JYYIaX4n4nj
FTT2U+0xno4xF4Rk1cXNfsPFVD1qqsothIeH5BVb5lB6FE+AFNprJ7y3kOwHwJZw
WsHfudqUntMjeVQ6gxhUvn08HOuk2s7jVE0BF5YysmBxRixokT9iGQ/sGx6qKdfY
xOqea77+XrJADUbKoPgKdKyGHrXzlducYDtzSLDVta96Sj5X2aKMCue5EBxU/0gU
ayt2e4JFVxC4Z/cySh++pILwTkGQNgAQI25xWP/bTiYa3pUlWGjtPS5dbUW54upQ
vTXtmNrqgoV61PvvHowh1YFGSmUFN2OmXokhUGgx/rV0IkLscOQ=
=OOSM
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

February 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Feb 1st
    11 Files
  • 2
    Feb 2nd
    0 Files
  • 3
    Feb 3rd
    0 Files
  • 4
    Feb 4th
    0 Files
  • 5
    Feb 5th
    0 Files
  • 6
    Feb 6th
    0 Files
  • 7
    Feb 7th
    0 Files
  • 8
    Feb 8th
    0 Files
  • 9
    Feb 9th
    0 Files
  • 10
    Feb 10th
    0 Files
  • 11
    Feb 11th
    0 Files
  • 12
    Feb 12th
    0 Files
  • 13
    Feb 13th
    0 Files
  • 14
    Feb 14th
    0 Files
  • 15
    Feb 15th
    0 Files
  • 16
    Feb 16th
    0 Files
  • 17
    Feb 17th
    0 Files
  • 18
    Feb 18th
    0 Files
  • 19
    Feb 19th
    0 Files
  • 20
    Feb 20th
    0 Files
  • 21
    Feb 21st
    0 Files
  • 22
    Feb 22nd
    0 Files
  • 23
    Feb 23rd
    0 Files
  • 24
    Feb 24th
    0 Files
  • 25
    Feb 25th
    0 Files
  • 26
    Feb 26th
    0 Files
  • 27
    Feb 27th
    0 Files
  • 28
    Feb 28th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Hosting By
Rokasec
close