7.5

CVE-2023-29451

Denial of service caused by a bug in the JSON parser

Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zabbix ≫ Zabbix Version <= 6.0.14
Zabbix ≫ Zabbix Version >= 6.4.2 <= 6.4.4
Zabbix ≫ Zabbix Version 6.4.0 Update alpha1
Zabbix ≫ Zabbix Version 6.4.0 Update beta1
Zabbix ≫ Zabbix Version 6.4.0 Update beta2
Zabbix ≫ Zabbix Version 6.4.0 Update beta3
Zabbix ≫ Zabbix Version 6.4.0 Update beta4
Zabbix ≫ Zabbix Version 6.4.0 Update beta5
Zabbix ≫ Zabbix Version 6.4.0 Update beta6
Zabbix ≫ Zabbix Version 6.4.0 Update rc2
Zabbix ≫ Zabbix Version 6.4.0 Update rc3
Zabbix ≫ Zabbix Version 6.4.0 Update rc4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.78% 0.518
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
security@zabbix.com 4.7 1.2 3.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://lists.debian.org/debian-lts-announce/2023/08/msg00027.html
https://support.zabbix.com/browse/ZBX-22587
Vendor Advisory