CVE-2020-36400
ZeroMQ vulnerability analysis and mitigation

Overview

ZeroMQ libzmq version 4.3.3 contains a heap-based buffer overflow vulnerability in the zmq::tcp_read function. This vulnerability is distinct from CVE-2021-20235 and was discovered on September 30, 2020 (OSS-Fuzz).

Technical details

The vulnerability is classified as a heap-based buffer overflow WRITE vulnerability that occurs in the zmq::tcp_read function, specifically within the call stack of zmq::stream_engine_base_t::read and zmq::stream_engine_base_t::in_event_internal. The issue was introduced in version 4.3.3 and has been assigned a HIGH severity rating (OSS-Fuzz-Vulns).

Impact

The vulnerability could potentially allow attackers to cause heap buffer overflow conditions, which might lead to arbitrary code execution or system crashes. The CVSS score of 7.0 indicates a high severity issue with potential impacts on confidentiality, integrity, and availability (Rapid7).

Exploitability

The vulnerability was discovered through OSS-Fuzz testing and was documented in their issue tracking system. The issue was introduced by commit b56195e995e0875afabf405826d97b1dd9817bb0 in version 4.3.3 (OSS-Fuzz-Vulns).

Mitigation and workarounds

The vulnerability was fixed in commit 397ac80850bf8d010fae23dd215db0ee2c677306, which addressed the issue by preventing unnecessary resizing of the static allocator. Users should upgrade to a version containing this fix (GitHub-Commit).

Additional resources


SourceThis report was generated using AI

Related ZeroMQ vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-36400CRITICAL9.8
  • ZeroMQ logoZeroMQ
  • zeromq
NoYesJul 01, 2021
CVE-2021-20236CRITICAL9.8
  • ZeroMQ logoZeroMQ
  • zeromq3
NoYesMay 28, 2021
CVE-2021-20235HIGH8.1
  • ZeroMQ logoZeroMQ
  • zeromq3
NoYesApr 01, 2021
CVE-2021-20237HIGH7.5
  • ZeroMQ logoZeroMQ
  • zeromq
NoYesMay 28, 2021
CVE-2021-20234MEDIUM6.5
  • ZeroMQ logoZeroMQ
  • zeromq
NoYesApr 01, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management