Vulnerability Name:

CVE-2019-6250 (CCN-155542)

Assigned:2019-01-08
Published:2019-01-08
Updated:2019-04-03
Summary:A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1. A v2_decoder.cpp zmq::v2_decoder_t::size_ready integer overflow allows an authenticated attacker to overwrite an arbitrary amount of bytes beyond the bounds of a buffer, which can be leveraged to run arbitrary code on the target system. The memory layout allows the attacker to inject OS commands into a data structure located immediately after the problematic buffer (i.e., it is not necessary to use a typical buffer-overflow exploitation technique that changes the flow of control).
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
7.9 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
6.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.0 High (CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-190
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2019-6250

Source: CCN
Type: IBM Security Bulletin 881778 (VRA - Vyatta 5600)
Vyatta 5600 vRouter Software Patches - Release 1801-v

Source: XF
Type: UNKNOWN
libzmq-cve20196250-code-exec(155542)

Source: CCN
Type: libzmq GIT Repository
Remote code execution vulnerability #3351

Source: CONFIRM
Type: Exploit, Patch, Third Party Advisory
https://github.com/zeromq/libzmq/issues/3351

Source: CONFIRM
Type: Third Party Advisory
https://github.com/zeromq/libzmq/releases/tag/v4.3.1

Source: GENTOO
Type: Third Party Advisory
GLSA-201903-22

Source: DEBIAN
Type: Third Party Advisory
DSA-4368

Vulnerable Configuration:Configuration 1:
  • cpe:/a:zeromq:libzmq:*:*:*:*:*:*:*:* (Version >= 4.2.0 and <= 4.2.5)
  • OR cpe:/a:zeromq:libzmq:*:*:*:*:*:*:*:* (Version >= 4.3.0 and < 4.3.1)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:zeromq:libzmq:4.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:zeromq:libzmq:4.2.5:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20196250
    V
    CVE-2019-6250
    2023-06-22
    oval:org.opensuse.security:def:7709
    P
    libzmq5-4.2.3-3.15.4 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:3170
    P
    libexif12-0.6.21-8.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3116
    P
    kbd-2.0.4-8.10.2 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3158
    P
    libaudit1-2.8.1-10.3.2 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94746
    P
    libzmq5-4.2.3-3.15.4 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:236
    P
    libzmq5-4.2.3-3.15.4 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:512
    P
    Security update for patch (Moderate)
    2022-06-02
    oval:org.opensuse.security:def:1165
    P
    Security update for rust1.56 (Moderate)
    2022-01-21
    oval:org.opensuse.security:def:112941
    P
    libzmq5-32bit-4.3.4-2.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:113293
    P
    python36-pyzmq-22.2.1-1.4 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:69815
    P
    Security update for java-1_8_0-ibm (Important) (in QA)
    2022-01-04
    oval:org.opensuse.security:def:1292
    P
    Security update for the Linux Kernel (Live Patch 3 for SLE 15 SP3) (Important)
    2021-12-14
    oval:org.opensuse.security:def:828
    P
    Security update for openssh (Important)
    2021-12-06
    oval:org.opensuse.security:def:106395
    P
    libzmq5-32bit-4.3.4-2.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:106705
    P
    python36-pyzmq-22.2.1-1.4 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:89756
    P
    libzmq5-4.2.3-3.3.2 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61601
    P
    libzmq5-4.2.3-3.3.2 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71342
    P
    libzmq5-4.2.3-3.3.2 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:103411
    P
    libzmq5-4.2.3-3.3.2 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:96721
    P
    libzmq5-4.2.3-3.3.2 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:69920
    P
    Security update for mariadb (Moderate)
    2021-08-25
    oval:org.opensuse.security:def:49297
    P
    Security update for python-PyYAML (Important)
    2021-08-24
    oval:org.opensuse.security:def:48159
    P
    libopenjp2-7-2.1.0-4.12.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47034
    P
    libjasper1-1.900.1-170.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48032
    P
    gstreamer-plugins-bad-1.8.3-17.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47048
    P
    libmodplug1-0.8.8.4-13.63 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48094
    P
    libarchive13-3.1.2-26.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47033
    P
    libjansson4-2.7-1.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47169
    P
    unixODBC-2.3.4-6.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47810
    P
    libwavpack1-4.60.99-5.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47362
    P
    libjavascriptcoregtk-4_0-18-2.12.5-1.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47824
    P
    mailman-2.1.17-1.18 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47809
    P
    libvte9-0.28.2-19.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47494
    P
    rsync-3.1.0-12.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47945
    P
    ant-1.9.4-3.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47586
    P
    cups-pk-helper-0.2.5-5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48138
    P
    libkpathsea6-6.2.0dev-22.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47734
    P
    libldap-2_4-2-2.4.41-18.40.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48270
    P
    perl-XML-LibXML-2.0019-6.3.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48190
    P
    libshibsp-lite6-2.5.5-6.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47948
    P
    apache-commons-httpclient-3.1-4.364 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48261
    P
    pcsc-ccid-1.4.25-4.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:2433
    P
    tiff-4.0.9-5.30.28 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2429
    P
    rsvg-view-2.42.9-3.6.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:71995
    P
    libzmq5-4.2.3-3.15.4 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1930
    P
    kernel-docs-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62254
    P
    libzmq5-4.2.3-3.15.4 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:49443
    P
    Security update for nodejs10 (Important)
    2021-07-14
    oval:org.opensuse.security:def:51603
    P
    Security update for openexr (Important)
    2021-06-24
    oval:org.opensuse.security:def:2439
    P
    argyllcms-1.9.2-2.27 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48510
    P
    libjavascriptcoregtk-4_0-18-2.12.5-1.12 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:2451
    P
    gstreamer-plugins-ugly-1.12.5-1.35 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48966
    P
    shotwell-0.22.0+git.20160103-15.6.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48724
    P
    gnome-shell-calendar-3.10.4-40.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48899
    P
    empathy-3.12.13-8.3.28 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:2465
    P
    libstaroffice-0_0-0-0.0.5-1.22 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48935
    P
    libnewt0_52-0.52.16-1.83 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48808
    P
    libwebkit2gtk-3_0-25-2.4.8-16.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48953
    P
    libwebkit2gtk3-lang-2.20.3-2.23.8 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:2471
    P
    pulseaudio-module-bluetooth-11.1-4.31 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48870
    P
    libreoffice-5.2.5.1-42.13 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71112
    P
    tftp-5.2-3.22 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48947
    P
    libsilc-1_1-2-1.1.10-24.128 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48965
    P
    sane-backends-32bit-1.0.24-3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48946
    P
    libreoffice-6.0.5.2-43.38.5 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:70999
    P
    liboath0-2.6.2-1.15 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48362
    P
    accountsservice-0.6.42-14.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:67759
    P
    Security update for the Linux Kernel (Live Patch 23 for SLE 15) (Important)
    2021-05-25
    oval:org.opensuse.security:def:51541
    P
    Security update for MozillaFirefox (Important)
    2021-04-27
    oval:org.opensuse.security:def:100597
    P
    (Moderate)
    2021-04-13
    oval:org.opensuse.security:def:64325
    P
    Security update for ceph (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:116821
    P
    libzmq5-4.2.3-3.8.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49037
    P
    libstaroffice-0_0-0-0.0.6-10.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2480
    P
    bogofilter-common-1.2.4-1.40 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:93884
    P
    libzmq5-4.2.3-3.8.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2504
    P
    libreoffice-6.1.3.2-6.28 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61917
    P
    libzmq5-4.2.3-3.8.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2520
    P
    bluez-cups-5.48-11.58 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2510
    P
    pidgin-plugin-otr-4.0.2-1.61 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71658
    P
    libzmq5-4.2.3-3.8.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2518
    P
    PackageKit-gstreamer-plugin-1.1.13-2.16 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107263
    P
    libzmq5-4.2.3-3.8.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:73137
    P
    libXt-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49541
    P
    libass-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49698
    P
    libtag-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50192
    P
    kernel-default-extra on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64412
    P
    libzmq5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49936
    P
    apache2-mod_apparmor on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49215
    P
    libpcsclite1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50265
    P
    Security update for openslp (Important)
    2020-12-01
    oval:org.opensuse.security:def:50161
    P
    libpurple on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50026
    P
    postgresql-contrib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49269
    P
    libzmq5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66472
    P
    libjansson-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50096
    P
    rsyslog-module-gssapi on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66564
    P
    libzmq5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73255
    P
    libzmq5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50313
    P
    Security update for ghostscript (Important)
    2020-12-01
    oval:org.opensuse.security:def:49092
    P
    firewall-macros on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50367
    P
    Security update for zeromq (Important)
    2020-12-01
    oval:org.opensuse.security:def:67659
    P
    libXvMC-devel on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.xenial:def:201962500000000
    V
    CVE-2019-6250 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-01-13
    oval:com.ubuntu.bionic:def:20196250000
    V
    CVE-2019-6250 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-01-13
    oval:com.ubuntu.cosmic:def:20196250000
    V
    CVE-2019-6250 on Ubuntu 18.10 (cosmic) - medium.
    2019-01-13
    oval:com.ubuntu.cosmic:def:201962500000000
    V
    CVE-2019-6250 on Ubuntu 18.10 (cosmic) - medium.
    2019-01-13
    oval:com.ubuntu.trusty:def:20196250000
    V
    CVE-2019-6250 on Ubuntu 14.04 LTS (trusty) - medium.
    2019-01-13
    oval:com.ubuntu.bionic:def:201962500000000
    V
    CVE-2019-6250 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-01-13
    oval:com.ubuntu.xenial:def:20196250000
    V
    CVE-2019-6250 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-01-13
    BACK
    zeromq libzmq *
    zeromq libzmq *
    debian debian linux 9.0
    zeromq libzmq 4.3.0
    zeromq libzmq 4.2.5