CVE-2012-6086: Medium severity zabbix server vulnerability
Published Jan 29, 2014
·Updated
libs/zbxmedia/eztexting.c in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.8rc1, and 2.1.x before 2.1.2 does not properly set the CURLOPTSSLVERIFYHOST option for libcurl, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Affected Software
22 affected components
Zabbix Zabbix=1.8.1
Zabbix Zabbix=1.8.10-rc1
Zabbix Zabbix=1.8.10-rc2
Zabbix Zabbix=1.8.15-rc1
Zabbix Zabbix=1.8.16
Zabbix Zabbix=2.0.0
Zabbix Zabbix=2.0.0-rc1
Zabbix Zabbix=2.0.0-rc2
Zabbix Zabbix=2.0.0-rc3
Zabbix Zabbix=2.0.0-rc4
Zabbix Zabbix=2.0.0-rc5
Zabbix Zabbix=2.0.0-rc6
Zabbix Zabbix=2.0.1
Zabbix Zabbix=2.0.1-rc1
Zabbix Zabbix=2.0.1-rc2
Zabbix Zabbix=2.0.2
Zabbix Zabbix=2.0.3
Zabbix Zabbix=2.0.4
Zabbix Zabbix=2.0.5
Zabbix Zabbix=2.0.6
Zabbix Zabbix=2.1.0
Zabbix Zabbix=2.1.1
Event History
Jan 29, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-6086?
CVE-2012-6086 is considered a high severity vulnerability due to its potential to allow man-in-the-middle attacks.
2
How do I fix CVE-2012-6086?
To fix CVE-2012-6086, upgrade Zabbix to version 1.8.18rc1, 2.0.8rc1, or 2.1.2 or later.
3
Which versions of Zabbix are affected by CVE-2012-6086?
CVE-2012-6086 affects Zabbix versions 1.8.x before 1.8.18rc1, 2.0.x before 2.0.8rc1, and 2.1.x before 2.1.2.
4
What kind of attack does CVE-2012-6086 allow?
CVE-2012-6086 allows attackers to perform man-in-the-middle attacks by spoofing SSL servers.
5
What component of Zabbix is affected by CVE-2012-6086?
CVE-2012-6086 affects the eztexting.c component of the Zabbix software.