peter bassill · operator
$ cve CVE-2019-13132 JSON

CVE-2019-13132

9.8
CRITICAL · CVSS 3.1 · EPSS 42.5% (pctl 99)

Patch early

EPSS 42.5% — above the 10% action threshold.

Description

In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled, may cause a stack overflow and overwrite the stack with arbitrary data, due to a buffer overflow in the library. Users running public servers with the above configuration are highly encouraged to upgrade as soon as possible, as there are no known mitigations.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS42.46% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploitnone known
Published2019-07-10
Last modified2026-06-17

Affected (4)

VendorProduct
canonicalubuntu linux
debiandebian linux
fedoraprojectfedora
zeromqlibzmq

References

→ the Explorer  ·  watch your stack  ·  NVD