QID 150734

Date Published: 2023-10-23

QID 150734: Zabbix Stack-buffer Overflow Vulnerability (CVE-2023-32722)

Zabbix is an open-source software tool to monitor IT infrastructure such as networks, servers, virtual machines, and cloud services.

The zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsing JSON files via zbx_json_open.

Affected version:
Zabbix version from 6.0.0 to 6.0.20
Zabbix version from 6.4.0 to 6.4.5

QID Detection Logic (Unauthenticated):
This QID sends a HTTP POST request to "api_jsonrpc.php" endpoint and checks the response body to confirm if the host is running vulnerable version of Zabbix Server.

Stack based buffer overflows usually lead to remote code execution.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade Zabbix to new version to remediate this vulnerability. For more information please refer to ZBX-23390.

    Vendor References

    CVEs related to QID 150734

    Software Advisories
    Advisory ID Software Component Link
    ZBX-23390 URL Logo support.zabbix.com/browse/ZBX-23390