CVE-2014-9721

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
03/06/2015
Last modified:
12/04/2025

Description

libzmq before 4.0.6 and 4.1.x before 4.1.1 allows remote attackers to conduct downgrade attacks and bypass ZMTP v3 protocol security mechanisms via a ZMTP v2 or earlier header.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zeromq:zeromq:*:*:*:*:*:*:*:* 4.0.5 (including)
cpe:2.3:a:zeromq:zeromq:4.1.0:rc1:*:*:*:*:*:*