[Git][security-tracker-team/security-tracker][master] CVE-2024-42327/zabbix not affecting bullseye
Tobias Frost (@tobi)
tobi at debian.org
Fri Dec 6 18:40:05 GMT 2024
Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1e46e6de by Tobias Frost at 2024-12-06T19:39:20+01:00
CVE-2024-42327/zabbix not affecting bullseye
vulnerable feature, userroles, is a new feature of Zabbix 6.0
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1734,9 +1734,11 @@ CVE-2024-42328 (When the webdriver for the Browser object downloads data from a
NOTE: webdriver introduced with vesion 7.0.0rc1 commit https://github.com/zabbix/zabbix/commit/4d22c15fe4499602e0da5399e3dd6dc9da03277b
CVE-2024-42327 (A non-admin user account on the Zabbix frontend with the default User ...)
- zabbix 1:7.0.1+dfsg-1 (bug #1088689)
+ [bullseye] - zabbix <not-affected> (Vulnerable code introduced later)
NOTE: https://support.zabbix.com/browse/ZBX-25623
NOTE: Fixed by: https://github.com/zabbix/zabbix/commit/9256f8d933a50a468ae36e7a40301aa761941612 (7.0.1rc1)
NOTE: Fixed by (merge commit): https://github.com/zabbix/zabbix/commit/39ff97dbf6f229a1b9c4f38db061aa73dd680828 (6.0.32rc1)
+ NOTE: Userroles introduced with version 6.0.0alpha1, commit https://github.com/zabbix/zabbix/commit/e5f4a103352a2e182c177236079bbe2a22907e45
CVE-2024-42326 (There was discovered a use after free bug in browser.c in the es_brows ...)
- zabbix 1:7.0.5+dfsg-1 (bug #1088689)
NOTE: https://support.zabbix.com/browse/ZBX-25622
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1e46e6de4ea6166521ab6ed732e28132519c03e2
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1e46e6de4ea6166521ab6ed732e28132519c03e2
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241206/8dacd2ca/attachment.htm>
More information about the debian-security-tracker-commits
mailing list