4.3
CVSSv2

CVE-2008-1353

Published: 17/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

zabbix_agentd in ZABBIX 1.4.4 allows remote malicious users to cause a denial of service (CPU and connection consumption) via multiple vfs.file.cksum commands with a special device node such as /dev/urandom or /dev/zero.

Vulnerable Product Search on Vulmon Subscribe to Product

zabbix zabbix 1.1.5

zabbix zabbix 1.4.2

zabbix zabbix 1.1.2

zabbix zabbix 1.4.3

zabbix zabbix 1.1.3

zabbix zabbix 1.1.4

Vendor Advisories

Debian Bug report logs - #471678 zabbix: CVE-2008-1353 local or remote DoS for authenticated hosts Package: zabbix; Maintainer for zabbix is Dmitry Smirnov <onlyjob@debianorg>; Reported by: Nico Golde <nion@debianorg> Date: Wed, 19 Mar 2008 14:03:04 UTC Severity: grave Tags: security Fixed in version zabbix/1:14 ...

Exploits

source: wwwsecurityfocuscom/bid/28244/info ZABBIX is prone to a denial-of-service vulnerability when handling specially crafted requests for file checksums An attacker can exploit this issue to cause the affected application to stop responding, denying service to legitimate users echo "vfsfilecksum[/dev/urandom]" | nc localhost echo ...