|
|
| |
|
| |
zabbix: multiple vulnerabilities
| Package(s): | zabbix |
CVE #(s): | CVE-2009-4499
CVE-2009-4501
|
| Created: | January 28, 2010 |
Updated: | February 3, 2010 |
| Description: |
From the CVE entry for CVE-2009-4499:
SQL injection vulnerability in the get_history_lastid function in the nodewatcher component in Zabbix Server before 1.6.8 allows remote attackers to execute arbitrary SQL commands via a crafted request, possibly related to the send_history_last_id function in zabbix_server/trapper/nodehistory.c.
From the CVE entry for CVE-2009-4501:
The zbx_get_next_field function in libs/zbxcommon/str.c in Zabbix Server before 1.6.8 allows remote attackers to cause a denial of service (crash) via a request that lacks expected separators, which triggers a NULL pointer dereference, as demonstrated using the Command keyword. |
| Alerts: |
|
( Log in to post comments)
|
|
|