ZABBIX Multiple Unspecified Remote Code Execution Vulnerabilities
BID:20416
Info
ZABBIX Multiple Unspecified Remote Code Execution Vulnerabilities
| Bugtraq ID: | 20416 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2006 12:00AM |
| Updated: | Oct 11 2006 04:09PM |
| Credit: | Max Vozeler and Ulf Harnhammar discovered these issues. |
| Vulnerable: |
ZABBIX ZABBIX 1.1.2 |
| Not Vulnerable: | |
Discussion
ZABBIX Multiple Unspecified Remote Code Execution Vulnerabilities
ZABBIX is prone to multiple unspecified remote code-execution vulnerabilities.
Reports indicate that these issues facilitate format-string and buffer-overflow attacks. A remote attacker may leverage these vulnerabilities to trigger denial-of-service conditions or to execute arbitrary code to gain unauthorized access to a vulnerable computer. This would occur in the context of the application.
ZABBIX version 1.1.2 is reported vulnerable; other versions may be affected as well.
ZABBIX is prone to multiple unspecified remote code-execution vulnerabilities.
Reports indicate that these issues facilitate format-string and buffer-overflow attacks. A remote attacker may leverage these vulnerabilities to trigger denial-of-service conditions or to execute arbitrary code to gain unauthorized access to a vulnerable computer. This would occur in the context of the application.
ZABBIX version 1.1.2 is reported vulnerable; other versions may be affected as well.
Exploit / POC
ZABBIX Multiple Unspecified Remote Code Execution Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A proof of concept is available:
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A proof of concept is available:
Solution / Fix
ZABBIX Multiple Unspecified Remote Code Execution Vulnerabilities
Solution:
An unofficial patch is available for version 1.1.2:
http://bugs.debian.org/cgi-bin/bugreport.cgi/zabbix.security.patch?bug=391388;msg=5;att=1http://bugs.debian.org/cgi-bin/bugreport.cgi/zabbix.security.patch?bug=391388;msg=5;att=1
Symantec has not verified the functionality of this patch.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
An unofficial patch is available for version 1.1.2:
http://bugs.debian.org/cgi-bin/bugreport.cgi/zabbix.security.patch?bug=391388;msg=5;att=1http://bugs.debian.org/cgi-bin/bugreport.cgi/zabbix.security.patch?bug=391388;msg=5;att=1
Symantec has not verified the functionality of this patch.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
ZABBIX Multiple Unspecified Remote Code Execution Vulnerabilities
References:
References:
- Debian Bug report logs - #391388 (Ulf Harnhammar
) - ZABBIX Homepage (ZABBIX)