[zabbix] [CVE-2007-6210] privilege escalation

Bug #174356 reported by disabled.user
260
Affects Status Importance Assigned to Milestone
zabbix (Ubuntu)
Fix Released
High
Unassigned
Nominated for Dapper by Emanuele Gentili
Edgy
Won't Fix
Undecided
Unassigned
Feisty
Won't Fix
Undecided
Unassigned
Gutsy
Won't Fix
Undecided
Unassigned

Bug Description

References:
[1] DSA-1420-1 (http://www.debian.org/security/2007/dsa-1420)
[2] Debian Bug #452682 (http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=452682)
[3] CVE-2007-6210 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6210)

Quoting [1]:
"Bas van Schaik discovered that the agentd process of Zabbix, a network monitor system, may run user-supplied commands as group id root, not zabbix, which may lead to a privilege escalation."

CVE References

Changed in zabbix:
assignee: nobody → emgent
importance: Undecided → High
status: New → In Progress
Changed in zabbix:
assignee: emgent → nobody
status: In Progress → Confirmed
Revision history for this message
William Grant (wgrant) wrote :

Fixed in Hardy.

Changed in zabbix:
status: Confirmed → Fix Released
Revision history for this message
Hew (hew) wrote :

Ubuntu Edgy Eft is no longer supported, so a SRU will not be issued for this release. Marking Edgy as Won't Fix.

Changed in zabbix:
status: New → Won't Fix
Revision history for this message
Hew (hew) wrote :

Ubuntu Feisty Fawn is no longer supported, so a SRU will not be issued for this release. Marking Feisty as Won't Fix.

Changed in zabbix:
status: New → Won't Fix
Revision history for this message
Sergio Zanchetta (primes2h) wrote :

The 18 month support period for Gutsy Gibbon 7.10 has reached its end of life -
http://www.ubuntu.com/news/ubuntu-7.10-eol . As a result, we are closing the
Gutsy task.

Changed in zabbix (Ubuntu Gutsy):
status: New → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.