Package: zabbix
Severity: grave
Tags: security

Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for zabbix.

CVE-2008-1353[0]:
| zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a
| denial of service (CPU and connection consumption) via multiple
| vfs.file.cksum commands with a special device node such as
| /dev/urandom or /dev/zero.

This should just work for authenticated hosts or hosts with 
a spoofed IP address. However from what I see this is also 
useable for local users.

If you fix this vulnerability please also include the CVE id
in your changelog entry.

For further information:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1353

Kind regards
Nico

-- 
Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.

Attachment: pgpE1ObsPhmYT.pgp
Description: PGP signature

Reply via email to