SB2014021206 - Fedora EPEL 6 update for zabbix20
Published: February 12, 2014 Updated: April 24, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Improper Authentication (CVE-ID: CVE-2014-1682)
The vulnerability allows a remote #AU# to manipulate data.
The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request.
2) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2013-5572)
The vulnerability allows a remote #AU# to gain access to sensitive information.
Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console access and reading the ldap_bind_password value in the HTML source code.
3) Input validation error (CVE-ID: CVE-2014-1685)
The vulnerability allows a remote #AU# to manipulate or delete data.
The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x before 2.2.2rc1 allows remote "Zabbix Admin" users to modify the media of arbitrary users via unspecified vectors.
Remediation
Install update from vendor's website.