[manjaro-security] [ASA-202009-16] zeromq: denial of service
foxboron at archlinux.org
Tue Oct 6 22:11:14 CEST 2020
Arch Linux Security Advisory ASA-202009-16
Date : 2020-09-26
CVE-ID : CVE-2020-15166
Package : zeromq
Type : denial of service
Remote : Yes
Link : https://security.archlinux.org/AVG-1219
The package zeromq before version 4.3.3-1 is vulnerable to denial of
Upgrade to 4.3.3-1.
# pacman -Syu "zeromq>=4.3.3-1"
The problem has been fixed upstream in version 4.3.3.
A denial of service has been found in libzmq before 4.3.3, allowing
unauthenticated clients to prevent legitimate clients from exchange any
message with a CURVE/ZAP-protected server.
A remote attacker might be able to cause a denial of service through a
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 833 bytes
Desc: not available
More information about the manjaro-security