CVE-2019-6250
A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1. A v2_decoder.cpp zmq::v2_decoder_t::size_ready integer overflow allows an authenticated attacker to overwrite an arbitrary amount of bytes beyond the bounds of a buffer, which can be leveraged to run arbitrary code on the target system. The memory layout allows the attacker to inject OS commands into a data structure located immediately after the problematic buffer (i.e., it is not necessary to use a typical buffer-overflow exploitation technique that changes the flow of control).
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 9.44% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- zeromq/libzmq · debian/debian linux
- Source
- cve@mitre.org
References
- https://github.com/zeromq/libzmq/issues/3351Exploit, Patch, Third Party Advisory
- https://github.com/zeromq/libzmq/releases/tag/v4.3.1Third Party Advisory
- https://security.gentoo.org/glsa/201903-22Third Party Advisory
- https://www.debian.org/security/2019/dsa-4368Third Party Advisory
- https://github.com/zeromq/libzmq/issues/3351Exploit, Patch, Third Party Advisory
- https://github.com/zeromq/libzmq/releases/tag/v4.3.1Third Party Advisory
- https://security.gentoo.org/glsa/201903-22Third Party Advisory
- https://www.debian.org/security/2019/dsa-4368Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.