Multiple format string vulnerabilities in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in information that would be recorded in the system log using (1) zabbix_log or (2) zabbix_syslog.
References
Configurations
History
21 Nov 2024, 00:23
Type | Values Removed | Values Added |
---|---|---|
References | () http://bugs.debian.org/cgi-bin/bugreport.cgi/zabbix.security.patch?bug=391388%3Bmsg=5%3Batt=1 - | |
References | () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=391388 - Exploit | |
References | () http://secunia.com/advisories/22313 - | |
References | () http://www.securityfocus.com/bid/20416 - | |
References | () http://www.vupen.com/english/advisories/2006/3959 - |
07 Nov 2023, 01:59
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2006-12-21 21:28
Updated : 2024-11-21 00:23
NVD link : CVE-2006-6692
Mitre link : CVE-2006-6692
CVE.ORG link : CVE-2006-6692
JSON object : View
Products Affected
zabbix
- zabbix
CWE