[ZBX-15867] Security vulnerability when processing discovery contents from proxy Created: 2019 Feb 20  Updated: 2024 Apr 10  Resolved: 2019 Mar 26

Status: Closed
Project: ZABBIX BUGS AND ISSUES
Component/s: Server (S)
Affects Version/s: 3.0.25, 4.0.6rc1
Fix Version/s: 3.0.26rc1, 4.0.6rc1, 4.2.0beta2, 4.2 (plan)

Type: Problem report Priority: Critical
Reporter: Vladislavs Sokurenko Assignee: Vladislavs Sokurenko
Resolution: Fixed Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Attachments: PNG File echo.png     PNG File traceroute.png    
Issue Links:
Causes
caused by ZBX-12349 CVE-2017-2824 zabbix: Multiple vulner... Closed
Team: Team A
Sprint: Sprint 49 (Feb 2019)
Story Points: 0.25

 Description   

It's possible to send specific network discovery contents to Zabbix server and make it to accept invalid DNS, resulting in such host being discovered:

Later if there are scripts that call HOST.DNS, for example script:

/usr/bin/traceroute {HOST.DNS}

It can open in something unexpected:



 Comments   
Comment by Vladislavs Sokurenko [ 2019 Feb 28 ]

Fixed in:

  • pre-3.0.26rc1 r91488
  • pre-4.0.6rc2 r91489
  • pre-4.2.0rc2 (trunk) r91490
Generated at Fri Apr 26 05:42:25 EEST 2024 using Jira 9.12.4#9120004-sha1:625303b708afdb767e17cb2838290c41888e9ff0.