UBUNTU-CVE-2017-2824
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-2824
UBUNTU-CVE-2017-2824
Summary:
Details: An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets can cause a command injection resulting in remote code execution. An attacker can make requests from an active Zabbix Proxy to trigger this vulnerability.
References: https://ubuntu.com/security/CVE-2017-2824, http://www.talosintelligence.com/reports/TALOS-2017-0325/, http://www.talosintelligence.com/reports/TALOS-2017-0326/, https://www.cve.org/CVERecord?id=CVE-2017-2824, https://ubuntu.com/security/notices/USN-4767-1
Affected packages
Package
Name: zabbix
Purl: pkg:deb/ubuntu/zabbix@1:2.2.2+dfsg-1ubuntu1+esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
