First published: Thu Dec 21 2006(Updated: )
Multiple format string vulnerabilities in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in information that would be recorded in the system log using (1) zabbix_log or (2) zabbix_syslog.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zabbix Server | =1.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6692 is considered to be of high severity due to its potential to cause denial of service and possible arbitrary code execution.
To fix CVE-2006-6692, upgrade to a version of Zabbix that is released after 20061006 where the vulnerability has been addressed.
CVE-2006-6692 affects versions of Zabbix before 20061006, including version 1.1.2.
The potential risks of CVE-2006-6692 include application crashes and the execution of arbitrary code, leading to security breaches.
Yes, CVE-2006-6692 can be exploited remotely if the attacker can manipulate the logging functions.