CVE-2019-13132
Last modified
CVE-2019-13132 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled, may cause a stack overflow and overwrite the stack with arbitrary data, due to a buffer overflow in the library. Users running public servers with the above configuration are highly encouraged to upgrade as soon as possible, as there are no known mitigations.. EPSS estimates a 42.46% chance of exploitation in the next 30 days.
Description
In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled, may cause a stack overflow and overwrite the stack with arbitrary data, due to a buffer overflow in the library. Users running public servers with the above configuration are highly encouraged to upgrade as soon as possible, as there are no known mitigations.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zeromq | Libzmq | < 4.0.9 |
| Zeromq | Libzmq | >= 4.1.0, < 4.1.7 |
| Zeromq | Libzmq | >= 4.2.0, < 4.3.2 |
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 18.10 |
| Canonical | Ubuntu Linux | 19.04 |
| Fedoraproject | Fedora | 29 |
| Fedoraproject | Fedora | 30 |
| Fedoraproject | Fedora | 31 |
References
- https://www.openwall.com/lists/oss-security/2019/07/08/6Mailing List, Release Notes, Third Party Advisory
- https://www.securityfocus.com/bid/109284Broken Link, Third Party Advisory, VDB Entry
- https://github.com/zeromq/libzmq/issues/3558Third Party Advisory
- https://github.com/zeromq/libzmq/releasesRelease Notes, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/07/msg00007.htmlMailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jul/13Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201908-17Third Party Advisory
- https://usn.ubuntu.com/4050-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4477Third Party Advisory
- https://www.openwall.com/lists/oss-security/2019/07/08/6Mailing List, Release Notes, Third Party Advisory
- https://www.securityfocus.com/bid/109284Broken Link, Third Party Advisory, VDB Entry
- https://github.com/zeromq/libzmq/issues/3558Third Party Advisory
- https://github.com/zeromq/libzmq/releasesRelease Notes, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/07/msg00007.htmlMailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jul/13Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201908-17Third Party Advisory
- https://usn.ubuntu.com/4050-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4477Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-13132?
How severe is CVE-2019-13132?
How do I fix CVE-2019-13132?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-13126An integer overflow in NATS Server before 2.0.2 allows a rem…7.5
- CVE-2019-13127An issue was discovered in mxGraph through 4.0.0, related to…
- CVE-2019-13128An issue was discovered on D-Link DIR-823G devices with firm…
- CVE-2019-13129On the Motorola router CX2L MWR04L 1.01, there is a stack co…
- CVE-2019-1313An information disclosure vulnerability exists in Microsoft …6.5
- CVE-2019-13131Super Micro SuperDoctor 5, when restrictions are not impleme…
- CVE-2019-13133ImageMagick before 7.0.8-50 has a memory leak vulnerability …5.5
- CVE-2019-13134ImageMagick before 7.0.8-50 has a memory leak vulnerability …5.5
- CVE-2019-13135ImageMagick before 7.0.8-50 has a "use of uninitialized valu…8.8
- CVE-2019-13136ImageMagick before 7.0.8-50 has an integer overflow vulnerab…
- CVE-2019-13137ImageMagick before 7.0.8-50 has a memory leak vulnerability …6.5
- CVE-2019-13139In Docker before 18.09.4, an attacker who is capable of supp…
Are you affected by CVE-2019-13132?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
