|
|
Log in / Subscribe / Register

zeromq: man-in-the-middle attack

Package(s):zeromq CVE #(s):CVE-2014-7202 CVE-2014-7203
Created:November 11, 2014 Updated:November 25, 2014
Description: From the CVE entries:

stream_engine.cpp in libzmq (aka ZeroMQ/C++)) 4.0.5 before 4.0.5 allows man-in-the-middle attackers to conduct downgrade attacks via a crafted connection request. (CVE-2014-7202)

libzmq (aka ZeroMQ/C++) 4.0.x before 4.0.5 does not ensure that nonces are unique, which allows man-in-the-middle attackers to conduct replay attacks via unspecified vectors. (CVE-2014-7203)

Alerts:
openSUSE openSUSE-SU-2014:1493-1 zeromq 2014-11-25
openSUSE openSUSE-SU-2014:1381-1 zeromq 2014-11-10

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds