ZeroMQ Multiple Security Bypass Vulnerabilities
BID:70157
Info
ZeroMQ Multiple Security Bypass Vulnerabilities
| Bugtraq ID: | 70157 |
| Class: | Design Error |
| CVE: |
CVE-2014-7202 CVE-2014-7203 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 26 2014 12:00AM |
| Updated: | Sep 30 2014 12:02AM |
| Credit: | Matthew Hawn |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
ZeroMQ Multiple Security Bypass Vulnerabilities
ZeroMQ is prone to a man-in-the-middle security-bypass vulnerability and a replay security-bypass vulnerability.
Attackers can exploit these issues to gain access to the sensitive information through a man-in-the-middle attack and bypass security restrictions or allow an attacker to perform replay attacks.
ZeroMQ 4.0.x through 4.0.4 are vulnerable.
ZeroMQ is prone to a man-in-the-middle security-bypass vulnerability and a replay security-bypass vulnerability.
Attackers can exploit these issues to gain access to the sensitive information through a man-in-the-middle attack and bypass security restrictions or allow an attacker to perform replay attacks.
ZeroMQ 4.0.x through 4.0.4 are vulnerable.
Exploit / POC
ZeroMQ Multiple Security Bypass Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
ZeroMQ Multiple Security Bypass Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
ZeroMQ Multiple Security Bypass Vulnerabilities
References:
References: