First published: Sat Dec 14 2013(Updated: )
The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zabbix Server | <=1.8.15 | |
Zabbix Server | =2.0.0 | |
Zabbix Server | =2.0.1 | |
Zabbix Server | =2.0.2 | |
Zabbix Server | =2.0.3 | |
Zabbix Server | =2.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1364 is considered a medium severity vulnerability due to its potential impact on LDAP configuration.
To fix CVE-2013-1364, upgrade Zabbix to version 1.8.16 or 2.0.5rc1 or later.
CVE-2013-1364 affects Zabbix versions prior to 1.8.16 and all 2.0.x versions before 2.0.5rc1.
CVE-2013-1364 allows remote attackers to override LDAP configurations, potentially leading to unauthorized access.
Yes, CVE-2013-1364 can impact user authentication by allowing unauthorized LDAP configuration overrides.