MEDIUM
zeromq: stream engine security can be downgraded by client.
Published Oct 8, 2014
4.3
MEDIUMCVSS 2.0
EPSS 2.02%
Description
stream_engine.cpp in libzmq (aka ZeroMQ/C++)) 4.0.5 before 4.0.5 allows man-in-the-middle attackers to conduct downgrade attacks via a crafted connection request.
Affected products
Remediation
Red Hat statement
This issue did not affect the versions of zeromq as shipped with Inktank Ceph Enterprise 1.2 and 1.3.
Weaknesses (0)
No CWE recorded.
References (13)
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00027.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00101.html vendor-advisoryx_refsource_SUSE
- http://seclists.org/oss-sec/2014/q3/754 mailing-listx_refsource_MLIST
- http://seclists.org/oss-sec/2014/q3/776 mailing-listx_refsource_MLIST
- http://secunia.com/advisories/62262 third-party-advisoryx_refsource_SECUNIA
- http://www.securityfocus.com/bid/70157 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2014-7202 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1147311 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96241 vdb-entryx_refsource_XF
- https://github.com/zeromq/libzmq/issues/1190 x_refsource_CONFIRM
- https://github.com/zeromq/libzmq/pull/1188 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2014-7202
- https://www.cve.org/CVERecord?id=CVE-2014-7202
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-updates/2014-11/msg00027.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-updates/2014-11/msg00101.html | vendor-advisoryx_refsource_SUSE | |
| http://seclists.org/oss-sec/2014/q3/754 | mailing-listx_refsource_MLIST | |
| http://seclists.org/oss-sec/2014/q3/776 | mailing-listx_refsource_MLIST | |
| http://secunia.com/advisories/62262 | third-party-advisoryx_refsource_SECUNIA | |
| http://www.securityfocus.com/bid/70157 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/security/cve/CVE-2014-7202 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1147311 | Issue Tracking | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/96241 | vdb-entryx_refsource_XF | |
| https://github.com/zeromq/libzmq/issues/1190 | x_refsource_CONFIRM | |
| https://github.com/zeromq/libzmq/pull/1188 | x_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2014-7202 | ||
| https://www.cve.org/CVERecord?id=CVE-2014-7202 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 8, 2014
Updated Aug 6, 2024
Reserved Sep 26, 2014
Link CVE-2014-7202
CISA Vulnrichment
Updated n/a