Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-42328

Опубликовано: 27 нояб. 2024
Источник: debian
EPSS Низкий

Описание

When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allocated only in curl_write_cb when receiving data. If the server's response is an empty document, then wd->data in the code below will remain NULL and an attempt to read from it will result in a crash.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zabbixfixed1:7.0.5+dfsg-1package
zabbixnot-affectedbookwormpackage
zabbixnot-affectedbullseyepackage

Примечания

  • https://support.zabbix.com/browse/ZBX-25624

  • webdriver introduced with commit https://github.com/zabbix/zabbix/commit/4d22c15fe4499602e0da5399e3dd6dc9da03277b (7.0.0rc1)

EPSS

Процентиль: 6%
0.00029
Низкий

Связанные уязвимости

CVSS3: 3.3
ubuntu
7 месяцев назад

When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allocated only in curl_write_cb when receiving data. If the server's response is an empty document, then wd->data in the code below will remain NULL and an attempt to read from it will result in a crash.

CVSS3: 3.3
nvd
7 месяцев назад

When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allocated only in curl_write_cb when receiving data. If the server's response is an empty document, then wd->data in the code below will remain NULL and an attempt to read from it will result in a crash.

CVSS3: 3.3
github
7 месяцев назад

When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allocated only in curl_write_cb when receiving data. If the server's response is an empty document, then wd->data in the code below will remain NULL and an attempt to read from it will result in a crash.

CVSS3: 3.3
fstec
7 месяцев назад

Уязвимость функции curl_write_cb() универсальной системы мониторинга Zabbix, позволяющая нарушителю вызвать отказ в обслуживании (DoS)

CVSS3: 8.8
redos
6 месяцев назад

Множественные уязвимости zabbix7-lts-server-pgsql

EPSS

Процентиль: 6%
0.00029
Низкий