[zeromq-announce] libzmq 4.3.2 has been released
Luca Boccassi
luca.boccassi at gmail.com
Mon Jul 8 18:10:50 CEST 2019
Hello everyone,
The ZeroMQ community is proud to announce the release of version 4.3.2!
Please note that this release fixes a severe security bug:
CVE-2019-13132: a remote, unauthenticated client connecting to a
libzmq application, running with a socket listening with CURVE
encryption/authentication enabled, may cause a stack overflow and
overwrite the stack with arbitrary data, due to a buffer overflow in
the library. Users running public servers with the above configuration
are highly encouraged to upgrade as soon as possible, as there are no
known mitigations. All versions from 4.0.0 and upwards are affected.
Thank you Fang-Pen Lin for finding the issue and reporting it!
https://github.com/zeromq/libzmq/issues/3558
New release:
https://github.com/zeromq/libzmq/releases/tag/v4.3.2
Distributable tarball and zip files can be found on the above link,
together with the full changelog.
Binary packages for the most common Linux distros and architectures can
be found here, for DEB and RPM respectively:
http://software.opensuse.org/download.html?project=network%3Amessaging%3Azeromq%3Arelease-stable&package=libzmq3-dev
http://software.opensuse.org/download.html?project=network%3Amessaging%3Azeromq%3Arelease-stable&package=zeromq-devel
This is a patch release. This release is ABI compatible with libzmq
4.1.2 and up.
Please report any issues on the Github tracker.
--
Kind regards,
Luca Boccassi
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 488 bytes
Desc: This is a digitally signed message part
URL: <https://lists.zeromq.org/pipermail/zeromq-announce/attachments/20190708/b8be5723/attachment.sig>
More information about the zeromq-announce
mailing list