ZABBIX 'process_trap()' NULL Pointer Dereference Denial Of Service Vulnerability
BID:37308
Info
ZABBIX 'process_trap()' NULL Pointer Dereference Denial Of Service Vulnerability
| Bugtraq ID: | 37308 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-4500 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2009 12:00AM |
| Updated: | Apr 16 2015 05:43PM |
| Credit: | Alexander Vladishev |
| Vulnerable: |
ZABBIX ZABBIX 1.6.5 ZABBIX ZABBIX 1.6.3 ZABBIX ZABBIX 1.6.2 ZABBIX ZABBIX 1.4.3 ZABBIX ZABBIX 1.4.2 ZABBIX ZABBIX 1.1.5 ZABBIX ZABBIX 1.1.4 ZABBIX ZABBIX 1.1.3 ZABBIX ZABBIX 1.1.2 |
| Not Vulnerable: |
ZABBIX ZABBIX 1.6.6 |
Discussion
ZABBIX 'process_trap()' NULL Pointer Dereference Denial Of Service Vulnerability
ZABBIX is prone to a denial-of-service vulnerability because of a NULL-pointer dereference.
Successful exploits may allow remote attackers to cause denial-of-service conditions. Given the nature of this issue, attackers may also be able to run arbitrary code, but this has not been confirmed.
Versions prior to ZABBIX 1.6.6 are vulnerable.
ZABBIX is prone to a denial-of-service vulnerability because of a NULL-pointer dereference.
Successful exploits may allow remote attackers to cause denial-of-service conditions. Given the nature of this issue, attackers may also be able to run arbitrary code, but this has not been confirmed.
Versions prior to ZABBIX 1.6.6 are vulnerable.
Exploit / POC
ZABBIX 'process_trap()' NULL Pointer Dereference Denial Of Service Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
ZABBIX 'process_trap()' NULL Pointer Dereference Denial Of Service Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
ZABBIX 'process_trap()' NULL Pointer Dereference Denial Of Service Vulnerability
References:
References:
- [#ZBX-993] DoS in Zabbix Server (Alexander Vladishev)