FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

libzmq4 -- V3 protocol handler vulnerable to downgrade attacks

Affected packages
4.0.0 <= libzmq4 < 4.0.6
4.1.0 <= libzmq4 < 4.1.1


VuXML ID 10a6d0aa-0b1c-11e5-bb90-002590263bf5
Discovery 2014-12-04
Entry 2015-06-10
Modified 2015-09-28

Pieter Hintjens reports:

It is easy to bypass the security mechanism in 4.1.0 and 4.0.5 by sending a ZMTP v2 or earlier header. The library accepts such connections without applying its security mechanism.


CVE Name CVE-2014-9721
FreeBSD PR ports/200502