CVE-2013-1364
Publication date 14 December 2013
Last updated 24 July 2024
Ubuntu priority
The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter.
Status
Package | Ubuntu Release | Status |
---|---|---|
zabbix | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|
Notes
seth-arnold
'high' severity is based on the assumption that users in zabbix may be able to execute arbitrary commands via monitoring agents. I have not determined if this is an accurate assumption.