MGASA-2014-0095
Dashboard / Vulnerabilities / MGASA-2014-0095
MGASA-2014-0095
Summary: Updated zabbix packages fix multiple vulnerabilities
Details: Updated zabbix packages fix security vulnerabilities: Zabbix before 2.0.11 allows remote authenticated users to discover the LDAP bind password by leveraging management-console access and reading the ldap_bind_password value in the HTML source code (CVE-2013-5572). Zabbix before 2.0.11 allows switching users without proper credentials when using HTTP authentication (CVE-2014-1682). In Zabbix before 2.0.11, the admin user is able to update media for other users (CVE-2014-1685).
References: https://advisories.mageia.org/MGASA-2014-0095.html, https://support.zabbix.com/browse/ZBX-6721, https://support.zabbix.com/browse/ZBX-7693, https://support.zabbix.com/browse/ZBX-7703, http://www.zabbix.com/rn2.0.11.php, https://bugs.mageia.org/show_bug.cgi?id=12574
Affected packages
Package
Name: zabbix
Purl: pkg:rpm/mageia/zabbix?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
