Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 591372 - <net-analyzer/zabbix-{2.2.14,3.0.5,3.2.0}: Unsanitized input in toggle_ids array in latest.php causes SQL injection
Summary: <net-analyzer/zabbix-{2.2.14,3.0.5,3.2.0}: Unsanitized input in toggle_ids ar...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2016-08-16 08:37 UTC by Agostino Sarubbo
Modified: 2016-11-30 08:19 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2016-08-16 08:37:36 UTC
From ${URL} :

It was found that Zabbix 2.2.x, 3.0.x and trunk suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the toggle_ids array in the latest.php page.

By exploiting this SQL injection vulnerability, an authenticated attacker (or guest user) is able to gain full access to the database. This would allow an attacker to escalate their privileges to a power user, compromise the database, or execute commands on the 
underlying database operating system.

Although the attacker needs to be authenticated in general, the system could also be at risk if the adversary has no user account. Zabbix offers a guest mode which provides a low privileged default account for users without password. If this guest mode is 
enabled, the SQL injection vulnerability can be exploited unauthenticated.

Upstream bug:

https://support.zabbix.com/browse/ZBX-11023

External Reference:

http://seclists.org/fulldisclosure/2016/Aug/60


@maintainer(s): since the fixed package is already in the tree, please let us know if it is ready for the stabilization or not.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2016-11-28 01:29:43 UTC
@ Arches,

please test and mark stable: =net-analyzer/zabbix-2.2.15
Comment 2 Agostino Sarubbo gentoo-dev 2016-11-29 10:42:14 UTC
amd64 stable
Comment 3 Agostino Sarubbo gentoo-dev 2016-11-29 10:44:36 UTC
x86 stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 4 Aaron Bauman (RETIRED) gentoo-dev 2016-11-30 08:19:41 UTC
Cleaned in coordination with maintainer (alicef):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=e1a18ca5c204792aab0a70ac8303b779cae8a3db

GLSA Vote: No