Bug#471678: zabbix: CVE-2008-1353 local or remote DoS for authenticated hosts

2008-03-25 Thread Nico Golde
Hi Michael, * Michael Ablassmeier <[EMAIL PROTECTED]> [2008-03-25 16:25]: > On Wed, Mar 19, 2008 at 03:01:49PM +0100, Nico Golde wrote: [...] > > This should just work for authenticated hosts or hosts with > > a spoofed IP address. However from what I see this is also > > useable for local users

Bug#471678: zabbix: CVE-2008-1353 local or remote DoS for authenticated hosts

2008-03-25 Thread Michael Ablassmeier
hi, On Wed, Mar 19, 2008 at 03:01:49PM +0100, Nico Golde wrote: > Hi, > the following CVE (Common Vulnerabilities & Exposures) id was > published for zabbix. > > CVE-2008-1353[0]: > | zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a > | denial of service (CPU and connection consum

Bug#471678: zabbix: CVE-2008-1353 local or remote DoS for authenticated hosts

2008-03-19 Thread Nico Golde
Package: zabbix Severity: grave Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for zabbix. CVE-2008-1353[0]: | zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a | denial of service (CPU and connection consumption) via multiple | vfs.file.