CVE-2023-29451: Denial of service caused by a bug in the JSON parser
Published Jul 13, 2023
·Updated
Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy.
Affected Software
12 affected components
Zabbix Zabbix<=6.0.14
Zabbix Zabbix>=6.4.2<=6.4.4
Zabbix Zabbix=6.4.0-alpha1
Zabbix Zabbix=6.4.0-beta1
Zabbix Zabbix=6.4.0-beta2
Zabbix Zabbix=6.4.0-beta3
Zabbix Zabbix=6.4.0-beta4
Zabbix Zabbix=6.4.0-beta5
Zabbix Zabbix=6.4.0-beta6
Zabbix Zabbix=6.4.0-rc2
Zabbix Zabbix=6.4.0-rc3
Zabbix Zabbix=6.4.0-rc4
Event History
Jul 13, 2023
CVE Published
via MITRE·09:29 AM
Data Sourced
via MITRE·09:29 AM
DescriptionSeverityWeakness
Data Sourced
10:15 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-29451.
2
What is the severity of CVE-2023-29451?
The severity of CVE-2023-29451 is high with a CVSS score of 7.5.
3
Which software is affected by CVE-2023-29451?
The Zabbix Server and Zabbix Proxy versions 6.0.14 to 6.4.4 are affected by CVE-2023-29451.
4
How does CVE-2023-29451 impact the system?
CVE-2023-29451 can cause a buffer overrun in the JSON parser library, leading to a crash of the Zabbix Server or a Zabbix Proxy.
5
How can I fix CVE-2023-29451?
To fix CVE-2023-29451, update to a patched version of Zabbix Server or Zabbix Proxy.