UBUNTU-CVE-2021-20234
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-20234
UBUNTU-CVE-2021-20234
Summary:
Details: An uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/pipe.cpp. This issue causes a client that connects to multiple malicious or compromised servers to crash. The highest threat from this vulnerability is to system availability.
References: https://ubuntu.com/security/CVE-2021-20234, https://github.com/zeromq/libzmq/pull/3918, https://github.com/zeromq/libzmq/security/advisories/GHSA-wfr2-29gj-5w87, https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=22037, https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=22123, https://ubuntu.com/security/notices/USN-4920-1, https://www.cve.org/CVERecord?id=CVE-2021-20234
Affected packages
Package
Name: zeromq3
Purl: pkg:deb/ubuntu/[email protected]+dfsg-2ubuntu0.1+esm3?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
