CVE-2013-6824
published 2013-12-19CVE-2013-6824: Zabbix before 1.8.19rc1, 2.0 before 2.0.10rc1, and 2.2 before 2.2.1rc1 allows remote Zabbix servers and proxies to execute arbitrary commands via a newline in…
PriorityP347high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.75%
84.6th percentile
Zabbix before 1.8.19rc1, 2.0 before 2.0.10rc1, and 2.2 before 2.2.1rc1 allows remote Zabbix servers and proxies to execute arbitrary commands via a newline in a flexible user parameter.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zabbix | < zabbix 1:2.2.0+dfsg-6 (bookworm) | zabbix 1:2.2.0+dfsg-6 (bookworm) |
| zabbix | zabbix | <= 1.8.18 | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | >= 0 < 1:2.2.0+dfsg-6 | 1:2.2.0+dfsg-6 |
| zabbix | zabbix | >= 0 < 1:2.2.0+dfsg-6 | 1:2.2.0+dfsg-6 |
| zabbix | zabbix | >= 0 < 1:2.2.0+dfsg-6 | 1:2.2.0+dfsg-6 |
| zabbix | zabbix | >= 0 < 1:2.2.0+dfsg-6 | 1:2.2.0+dfsg-6 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fvmr-q9wm-2vfr: Zabbix before 1
ghsa_unreviewed·2022-05-17
CVE-2013-6824 [HIGH] CWE-94 GHSA-fvmr-q9wm-2vfr: Zabbix before 1
Zabbix before 1.8.19rc1, 2.0 before 2.0.10rc1, and 2.2 before 2.2.1rc1 allows remote Zabbix servers and proxies to execute arbitrary commands via a newline in a flexible user parameter.
OSV
CVE-2013-6824: Zabbix before 1
osv·2013-12-19·CVSS 7.5
CVE-2013-6824 [HIGH] CVE-2013-6824: Zabbix before 1
Zabbix before 1.8.19rc1, 2.0 before 2.0.10rc1, and 2.2 before 2.2.1rc1 allows remote Zabbix servers and proxies to execute arbitrary commands via a newline in a flexible user parameter.
Debian
CVE-2013-6824: zabbix - Zabbix before 1.8.19rc1, 2.0 before 2.0.10rc1, and 2.2 before 2.2.1rc1 allows re...
vendor_debian·2013·CVSS 7.5
CVE-2013-6824 [HIGH] CVE-2013-6824: zabbix - Zabbix before 1.8.19rc1, 2.0 before 2.0.10rc1, and 2.2 before 2.2.1rc1 allows re...
Zabbix before 1.8.19rc1, 2.0 before 2.0.10rc1, and 2.2 before 2.2.1rc1 allows remote Zabbix servers and proxies to execute arbitrary commands via a newline in a flexible user parameter.
Scope: local
bookworm: resolved (fixed in 1:2.2.0+dfsg-6)
bullseye: resolved (fixed in 1:2.2.0+dfsg-6)
forky: resolved (fixed in 1:2.2.0+dfsg-6)
sid: resolved (fixed in 1:2.2.0+dfsg-6)
trixie: resolved (fixed in 1:2.2.0+dfsg-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6824 zabbix: remote command execution from zabbix server
bugzilla·2013-12-04·CVSS 7.5
CVE-2013-6824 [HIGH] CVE-2013-6824 zabbix: remote command execution from zabbix server
CVE-2013-6824 zabbix: remote command execution from zabbix server
Zabbix agent is found to be vulnerable to remote command execution from the Zabbix server in some cases.
It is found that if a flexible user parameter is configured in the agent, including a newline in the parameters will execute newline section as a separate command even if UnsafeUserParameters are disabled.
This type of attack is known to be only possible from Zabbix server or Zabbix proxy systems that are explicitly allowed in the agent configuration. Only flexible user parameters are vulnerable, static ones are not.
References:
https://bugs.gentoo.org/show_bug.cgi?id=493250
https://support.zabbix.com/browse/ZBX-7479
Discussion:
Created zabbix tracking bugs for this issue:
Affects: fedora-all [bug 1037942]
Affects:
Bugzilla
CVE-2013-6824 zabbix20: zabbix: remote command execution from zabbix server [epel-all]
bugzilla·2013-12-04·CVSS 7.5
CVE-2013-6824 [HIGH] CVE-2013-6824 zabbix20: zabbix: remote command execution from zabbix server [epel-all]
CVE-2013-6824 zabbix20: zabbix: remote command execution from zabbix server [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note:
Bugzilla
CVE-2013-6824 zabbix: remote command execution from zabbix server [fedora-all]
bugzilla·2013-12-04·CVSS 7.5
CVE-2013-6824 [HIGH] CVE-2013-6824 zabbix: remote command execution from zabbix server [fedora-all]
CVE-2013-6824 zabbix: remote command execution from zabbix server [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue af
Bugzilla
CVE-2013-6824 zabbix: remote command execution from zabbix server [epel-all]
bugzilla·2013-12-04·CVSS 7.5
CVE-2013-6824 [HIGH] CVE-2013-6824 zabbix: remote command execution from zabbix server [epel-all]
CVE-2013-6824 zabbix: remote command execution from zabbix server [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue
http://security.gentoo.org/glsa/glsa-201401-26.xmlhttp://www.zabbix.com/rn1.8.19rc1.phphttp://www.zabbix.com/rn2.0.10rc1.phphttp://www.zabbix.com/rn2.2.1rc1.phphttps://support.zabbix.com/browse/ZBX-7479http://security.gentoo.org/glsa/glsa-201401-26.xmlhttp://www.zabbix.com/rn1.8.19rc1.phphttp://www.zabbix.com/rn2.0.10rc1.phphttp://www.zabbix.com/rn2.2.1rc1.phphttps://support.zabbix.com/browse/ZBX-7479
2013-12-19
Published