rpm package
suse/zeromq&distro=SUSE Manager Client Tools 12
pkg:rpm/suse/zeromq&distro=SUSE%20Manager%20Client%20Tools%2012
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-3698 | — | < 4.0.4-15.8.1 | 4.0.4-15.8.1 | Feb 28, 2020 | UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue | ||
| CVE-2019-13132 | — | < 4.0.4-15.3.1 | 4.0.4-15.3.1 | Jul 10, 2019 | In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled, may cause a stack overflow and overwrite the stack with ar | ||
| CVE-2016-9566 | Hig | 7.8 | < 4.0.4-15.8.1 | 4.0.4-15.8.1 | Dec 15, 2016 | base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565. |
- CVE-2019-3698Feb 28, 2020affected < 4.0.4-15.8.1fixed 4.0.4-15.8.1
UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue
- CVE-2019-13132Jul 10, 2019affected < 4.0.4-15.3.1fixed 4.0.4-15.3.1
In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled, may cause a stack overflow and overwrite the stack with ar
- affected < 4.0.4-15.8.1fixed 4.0.4-15.8.1
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.