CVE-2013-1364
published 2013-12-14CVE-2013-1364: The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter.
PriorityP429medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
2.17%
80.4th percentile
The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zabbix | < zabbix 1:2.0.4+dfsg-2 (bookworm) | zabbix 1:2.0.4+dfsg-2 (bookworm) |
| zabbix | zabbix | <= 1.8.15 | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | >= 0 < 1:2.0.4+dfsg-2 | 1:2.0.4+dfsg-2 |
| zabbix | zabbix | >= 0 < 1:2.0.4+dfsg-2 | 1:2.0.4+dfsg-2 |
| zabbix | zabbix | >= 0 < 1:2.0.4+dfsg-2 | 1:2.0.4+dfsg-2 |
| zabbix | zabbix | >= 0 < 1:2.0.4+dfsg-2 | 1:2.0.4+dfsg-2 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_redhat7.2HIGH
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Kernel: drm/i915: heap writing overflow
vendor_redhat·2013-03-11·CVSS 7.2
CVE-2013-0913 [HIGH] Kernel: drm/i915: heap writing overflow
Kernel: drm/i915: heap writing overflow
Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel through 3.8.3, as used in Google Chrome OS before 25.0.1364.173 and other products, allows local users to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted application that triggers many relocation copies, and potentially leads to a race condition.
Statement: This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5.
This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise MRG 2 may addres
Red Hat
icu: Race condition leading to a use-after-free
vendor_redhat·2013-02-21·CVSS 6.8
CVE-2013-0900 [MEDIUM] CWE-416 icu: Race condition leading to a use-after-free
icu: Race condition leading to a use-after-free
Race condition in the International Components for Unicode (ICU) functionality in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Package: icu (Red Hat Enterprise Linux 5) - Will not fix
Package: icu (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2013-1364: zabbix - The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows r...
vendor_debian·2013·CVSS 5.0
CVE-2013-1364 [MEDIUM] CVE-2013-1364: zabbix - The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows r...
The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter.
Scope: local
bookworm: resolved (fixed in 1:2.0.4+dfsg-2)
bullseye: resolved (fixed in 1:2.0.4+dfsg-2)
forky: resolved (fixed in 1:2.0.4+dfsg-2)
sid: resolved (fixed in 1:2.0.4+dfsg-2)
trixie: resolved (fixed in 1:2.0.4+dfsg-2)
GHSA
GHSA-vq34-c5hg-7r26: The user
ghsa_unreviewed·2022-05-17
CVE-2013-1364 [MEDIUM] CWE-287 GHSA-vq34-c5hg-7r26: The user
The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter.
OSV
CVE-2013-1364: The user
osv·2013-12-14·CVSS 5.0
CVE-2013-1364 [MEDIUM] CVE-2013-1364: The user
The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter.
No detection rules found.
Bugzilla
CVE-2013-0900 icu: Race condition leading to a use-after-free
bugzilla·2013-03-05·CVSS 6.8
CVE-2013-0900 [MEDIUM] CVE-2013-0900 icu: Race condition leading to a use-after-free
CVE-2013-0900 icu: Race condition leading to a use-after-free
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-0900 to the following vulnerability:
Race condition in the International Components for Unicode (ICU) functionality in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
References:
[1] https://code.google.com/p/chromium/issues/detail?id=152442 (private)
[2] http://googlechromereleases.blogspot.com/2013/02/stable-channel-update_21.html
Other references:
[3] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=702346
[4] http://bugs.icu-project.org/trac/ticket/9737
[5] http://bugs.icu-project.org/trac/chang
Bugzilla
CVE-2013-1364 zabbix: possible to override LDAP configuration parameters via the API [fedora-all]
bugzilla·2013-01-19·CVSS 5.0
CVE-2013-1364 [MEDIUM] CVE-2013-1364 zabbix: possible to override LDAP configuration parameters via the API [fedora-all]
CVE-2013-1364 zabbix: possible to override LDAP configuration parameters via the API [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please
Bugzilla
CVE-2013-1364 zabbix: possible to override LDAP configuration parameters via the API [epel-6]
bugzilla·2013-01-19·CVSS 5.0
CVE-2013-1364 [MEDIUM] CVE-2013-1364 zabbix: possible to override LDAP configuration parameters via the API [epel-6]
CVE-2013-1364 zabbix: possible to override LDAP configuration parameters via the API [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6
Bugzilla
CVE-2013-1364 zabbix: possible to override LDAP configuration parameters via the API [epel-6]
bugzilla·2013-01-19·CVSS 5.0
CVE-2013-1364 [MEDIUM] CVE-2013-1364 zabbix: possible to override LDAP configuration parameters via the API [epel-6]
CVE-2013-1364 zabbix: possible to override LDAP configuration parameters via the API [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6
Bugzilla
CVE-2013-1364 zabbix: possible to override LDAP configuration parameters via the API
bugzilla·2013-01-19·CVSS 5.0
CVE-2013-1364 [MEDIUM] CVE-2013-1364 zabbix: possible to override LDAP configuration parameters via the API
CVE-2013-1364 zabbix: possible to override LDAP configuration parameters via the API
It was reported [1] that the user.login method in Zabbix would accept a 'cnf' parameter containing the configuration parameters to use for LDAP authentication, which would override the configuration stored in the database. This can be used to authenticate to Zabbix using a completely different LDAP application (e.g. authenticate to Zabbix using some other LDAP directory the attacker has credentials for).
This has been corrected in upstream versions 2.1.0 r32446, 2.0.5rc1 r32444 and 1.8.16rc1 r32442. Patches are attached to the upstream bug report.
[1] https://support.zabbix.com/browse/ZBX-6097
Discussion:
Created zabbix tracking bugs for this issue
Affects: epel-6 [bug 901876]
Affects: fedora-all [bu
http://secunia.com/advisories/55824http://security.gentoo.org/glsa/glsa-201311-15.xmlhttp://www.securityfocus.com/bid/57471http://www.zabbix.com/rn1.8.16.phphttp://www.zabbix.com/rn2.0.5rc1.phphttps://support.zabbix.com/browse/ZBX-6097http://secunia.com/advisories/55824http://security.gentoo.org/glsa/glsa-201311-15.xmlhttp://www.securityfocus.com/bid/57471http://www.zabbix.com/rn1.8.16.phphttp://www.zabbix.com/rn2.0.5rc1.phphttps://support.zabbix.com/browse/ZBX-6097
2013-12-14
Published