VYPR
High severity8.1NVD Advisory· Published Apr 1, 2021· Updated Jun 17, 2026

CVE-2021-20235

CVE-2021-20235

Description

There's a flaw in the zeromq server in versions before 4.3.3 in src/decoder_allocators.hpp. The decoder static allocator could have its sized changed, but the buffer would remain the same as it is a static buffer. A remote, unauthenticated attacker who sends a crafted request to the zeromq server could trigger a buffer overflow WRITE of arbitrary data if CURVE/ZAP authentication is not enabled. The greatest impact of this flaw is to application availability, data integrity, and confidentiality.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Zeromq/Libzmq2 versions
    cpe:2.3:a:zeromq:libzmq:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:zeromq:libzmq:*:*:*:*:*:*:*:*range: >=4.2.0,<4.3.3
    • (no CPE)range: <4.3.3
  • Zeromq/Zeromqllm-fuzzy
    Range: <4.3.3
  • zeromq/zeromq serverdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.