CVE-2009-4500: Buffer Overflow
Published Dec 31, 2009
·Updated
The processtrap function in trapper/trapper.c in Zabbix Server before 1.6.6 allows remote attackers to cause a denial of service (crash) via a crafted request with data that lacks an expected : (colon) separator, which triggers a NULL pointer dereference.
Affected Software
8 affected components
Zabbix Zabbix<=1.4.6
Zabbix Zabbix=1.1.2
Zabbix Zabbix=1.1.3
Zabbix Zabbix=1.1.4
Zabbix Zabbix=1.1.5
Zabbix Zabbix=1.4.2
Zabbix Zabbix=1.4.3
Zabbix Zabbix=1.4.4
Event History
Dec 31, 2009
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-4500?
CVE-2009-4500 has a severity rating that indicates potential denial of service due to a crash.
2
How do I fix CVE-2009-4500?
To fix CVE-2009-4500, upgrade to Zabbix Server version 1.6.6 or later.
3
What versions of Zabbix are affected by CVE-2009-4500?
CVE-2009-4500 affects Zabbix versions 1.1.2 through 1.4.6.
4
What type of attack does CVE-2009-4500 allow?
CVE-2009-4500 allows remote attackers to cause a denial of service via crafted requests.
5
What function is primarily involved in the CVE-2009-4500 vulnerability?
The process_trap function is primarily involved in the CVE-2009-4500 vulnerability.