CVE-2014-7202
Publication date 8 October 2014
Last updated 24 July 2024
Ubuntu priority
stream_engine.cpp in libzmq (aka ZeroMQ/C++)) 4.0.5 before 4.0.5 allows man-in-the-middle attackers to conduct downgrade attacks via a crafted connection request.
From the Ubuntu Security Team
Matthew Hawn discovered that ZeroMQ did not properly validate the security handshake. A remote attacker could conduct a downgrade attack via a crafted connection request.
Status
Package | Ubuntu Release | Status |
---|---|---|
zeromq | 18.04 LTS bionic | Not in release |
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|
zeromq3 | 18.04 LTS bionic |
Not affected
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Fixed 4.0.4+dfsg-2ubuntu0.1
|
|