UBUNTU-CVE-2021-20237
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-20237
UBUNTU-CVE-2021-20237
Summary:
Details: An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3. This flaw allows a remote unauthenticated attacker to send crafted PUB messages that consume excessive memory if the CURVE/ZAP authentication is disabled on the server, causing a denial of service. The highest threat from this vulnerability is to system availability.
References: https://ubuntu.com/security/CVE-2021-20237, https://github.com/zeromq/libzmq/security/advisories/GHSA-4p5v-h92w-6wxw, https://ubuntu.com/security/notices/USN-4920-1, https://www.cve.org/CVERecord?id=CVE-2021-20237
Affected packages
Package
Name: zeromq3
Purl: pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-apps/bionic
Affected ranges
Type: ECOSYSTEM
Events:
