[ASA-202009-15] lib32-zeromq: denial of service
foxboron at archlinux.org
Tue Oct 6 20:10:57 UTC 2020
Arch Linux Security Advisory ASA-202009-15
Date : 2020-09-26
CVE-ID : CVE-2020-15166
Package : lib32-zeromq
Type : denial of service
Remote : Yes
Link : https://security.archlinux.org/AVG-1220
The package lib32-zeromq before version 4.3.3-1 is vulnerable to denial
Upgrade to 4.3.3-1.
# pacman -Syu "lib32-zeromq>=4.3.3-1"
The problem has been fixed upstream in version 4.3.3.
A denial of service has been found in libzmq before 4.3.3, allowing
unauthenticated clients to prevent legitimate clients from exchange any
message with a CURVE/ZAP-protected server.
A remote attacker might be able to cause a denial of service through a
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 833 bytes
Desc: not available
More information about the arch-security