|
|
Log in / Subscribe / Register

Debian alert DLA-4473-1 (zabbix)

From:  rouca@debian.org
To:  <debian-lts-announce@lists.debian.org>
Subject:  [SECURITY] [DLA 4473-1] zabbix security update
Date:  Sun, 08 Feb 2026 17:13:35 +0100
Message-ID:  <3352802cf3250187ca8e94873d0cb411@debian.org>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4473-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Bastien Roucariès February 08, 2026 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : zabbix Version : 1:5.0.47+dfsg-0+deb11u1 CVE ID : CVE-2025-27234 zabbix a popular network monitoring solution was affected by a vulnerabilty. Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution. For Debian 11 bullseye, this problem has been fixed in version 1:5.0.47+dfsg-0+deb11u1. We recommend that you upgrade your zabbix packages. For the detailed security status of zabbix please refer to its security tracker page at: https://security-tracker.debian.org/tracker/zabbix Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmmIti8ACgkQADoaLapB CF/8zhAApg7e7zVGZZQwIKmwVyedO6KsmB5HH6gQCF3RYfVRvMLE+ZTQJMcKPWXj qrpWJi76s2i+tVznKA5x0RlK+LBtnM01gNNMXgh3CVNB/JqIBg+JoqOJ6LaouDzY qT9XbHt1jRahPDMVq8j3cbxLcOkwRlO6mONqGZrYyzsFW9siXIjyPX3B6PjHhegj J5ZBzpY0JF6rdAw/2qOIiN14wJCu2YH0KZvYa+xsrdn+zZR6pmZZJcAYosCG2Vop iJwYVq5R7Sq1FcEWJOgkXU1wuYSpzD78k2YZrIHkDnIz+8YFmh38WrtEiRofVHma L11i32Z9M6Cb+qKEgNhvX9DHO/0C66HsqSEFpT3RLIB+aOWObANopLJ0W3F+zXpd lNnCXLiyhvkg8i9/sn+MNy93Oof4Qu/HGr9gODP9SbyzZjOeXPyyuGc7hzwpDOTA z3JiNAtdDNqo4lI9EsqAEPz+8zR9IiEOpGBtftWLwGp2Jn28d++gtCflv9ObFUSn 0E435ACEeIe84XrBv4AvmpcAFVcQUFnME9agSUE1rPUYN3oCCcLTjAlE+lzx+bIA cL01VnwShvpKUCmopFarXSLGGk+bdD0mAFwt1+Y9nzan7LMa4FPZzXCugX15l+mW N1Vm1BbPVGBo3vNh8lmmR5ZZ31857ibWpXb1KAcKlSJhn8MWEEQ= =eoRk -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds