CVE-2011-3263Zabbix vulnerability

CWE-3995 documents5 sources
Severity
5.0MEDIUMNVD
EPSS
0.5%
top 35.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 19
Latest updateMay 17

Description

zabbix_agentd in Zabbix before 1.8.6 and 1.9.x before 1.9.4 allows context-dependent attackers to cause a denial of service (CPU consumption) by executing the vfs.file.cksum command for a special device, as demonstrated by the /dev/urandom device.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/zabbix< zabbix 1:1.8.6-1 (bookworm)
Debianzabbix/zabbix< 1:1.8.6-1+3
NVDzabbix/zabbix1.8.5+52

Patches

🔴Vulnerability Details

2
GHSA
GHSA-39vx-jv7h-w8ch: zabbix_agentd in Zabbix before 12022-05-17
OSV
CVE-2011-3263: zabbix_agentd in Zabbix before 12011-08-19

📋Vendor Advisories

1
Debian
CVE-2011-3263: zabbix - zabbix_agentd in Zabbix before 1.8.6 and 1.9.x before 1.9.4 allows context-depen...2011

💬Community

1
Bugzilla
CVE-2011-2904 CVE-2011-3263 CVE-2011-3264 zabbix: multiple flaws in zabbix < 1.8.62011-08-08