ZABBIX daemon_start Local Privilege Escalation Vulnerability
BID:26680
Info
ZABBIX daemon_start Local Privilege Escalation Vulnerability
| Bugtraq ID: | 26680 |
| Class: | Design Error |
| CVE: |
CVE-2007-6210 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 03 2007 12:00AM |
| Updated: | May 07 2015 05:04PM |
| Credit: | Bas van Schaik is credited with the discovery of this vulnerability. |
| Vulnerable: |
ZABBIX ZABBIX 1.4.2 ZABBIX ZABBIX 1.1.4 Red Hat Fedora 7 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
ZABBIX ZABBIX 1.4.3 |
Discussion
ZABBIX daemon_start Local Privilege Escalation Vulnerability
ZABBIX is prone to a local privilege-escalation vulnerability.
An attacker can exploit this issue to execute commands with superuser privileges. Successfully exploiting this issue will result in the complete compromise of affected computers.
This issue affects ZABBIX 1.4.2; prior versions may also be affected.
ZABBIX is prone to a local privilege-escalation vulnerability.
An attacker can exploit this issue to execute commands with superuser privileges. Successfully exploiting this issue will result in the complete compromise of affected computers.
This issue affects ZABBIX 1.4.2; prior versions may also be affected.
Exploit / POC
ZABBIX daemon_start Local Privilege Escalation Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
ZABBIX daemon_start Local Privilege Escalation Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
ZABBIX daemon_start Local Privilege Escalation Vulnerability
References:
References:
- UserCommands executed with gid set to root (abi)
- zabbix-agent runs as user 'zabbix' with gid=0 (root) ( Bas van Schaik)
- [SECURITY] [DSA 1420-1] New zabbix packages fix privilege escalation (Thijs Kinkhorst
)