Input validation error - CVE-2014-1685

 

Input validation error - CVE-2014-1685

Published: May 8, 2014 / Updated: August 4, 2020


Vulnerability identifier: #VU33853
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-1685
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to manipulate or delete data.

The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x before 2.2.2rc1 allows remote "Zabbix Admin" users to modify the media of arbitrary users via unspecified vectors.


Affected software

zabbix (Alpine package)
net-snmp (Alpine package)
zabbix
zabbix20
Fedora

How to mitigate CVE-2014-1685

Install update from vendor's website.

zabbix (Alpine package) - addressed in versions 1.8.20-r0, 2.0.11-r0
net-snmp (Alpine package) - update to 5.7.1-r4
zabbix - update to 1.8.20-1.el6
zabbix20 - addressed in versions 2.0.11-1.el5, 2.0.11-1.el6

External References

Related Security Bulletins