A stack buffer overflow exists in ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2. When a remote, unauthenticated client connects to a libzmq application with a socket listening and CURVE encryption/authentication enabled, the client can trigger a buffer overflow, allowing arbitrary data to be written to the stack. This is due to improper bounds checking in the library's handling of authentication data.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a complete lab and exploit kit for CVE-2019-13132, a stack buffer overflow in libzmq's CURVE INITIATE handshake processing. It is not a scanner or detector; it is a working remote code execution proof-of-concept with a reproducible Dockerized environment. The main exploit logic is in exploit.py, which implements enough of the ZMTP/CURVE handshake to send a valid HELLO, receive and decrypt WELCOME using the hardcoded server public key, extract the genuine cookie, and then send an oversized INITIATE frame that overflows process_initiate(). The overflow payload is simple but functional: 456 bytes of filler followed by an 8-byte overwritten return address pointing to lab_trampoline() in the lab server binary. The repository structure supports end-to-end exploitation. server-curve.c is the intentionally vulnerable target application: a CURVE-enabled ZeroMQ REP server compiled without stack protections and without PIE. It embeds a fixed CURVE keypair and includes lab_trampoline(), which serves as the post-exploitation payload by creating /tmp/pwned-13132, copying /proc/self/status and /etc/hostname into it, and exiting the process. compute_offsets.py extracts static offsets and the trampoline symbol address from the built artifacts. calibrate.sh writes profile.json from those offsets. start_server.sh launches the vulnerable server on tcp://0.0.0.0:5556, entrypoint.sh disables ASLR and initializes the lab, and run_lab_test.sh automates exploitation and proof verification. The exploit capability is network-based RCE against a vulnerable CURVE-enabled libzmq server. In this repository, exploitation is tightly coupled to the lab build: it assumes a known server public key, a fixed trampoline address, disabled ASLR, and a non-PIE/no-canary binary. The code does not attempt broad target fingerprinting or dynamic gadget discovery; instead it uses built-in or profile-supplied offsets, making it operational for the provided environment rather than broadly weaponized. Notable fingerprintable observables include the target bind/listen endpoint tcp://0.0.0.0:5556, local test target 127.0.0.1:5556, the proof file /tmp/pwned-13132, and the hardcoded CURVE public key used by the exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.