Vulnerability Name: | CVE-2008-1353 (CCN-41196) | ||||||||
Assigned: | 2008-03-13 | ||||||||
Published: | 2008-03-13 | ||||||||
Updated: | 2018-10-11 | ||||||||
Summary: | zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a denial of service (CPU and connection consumption) via multiple vfs.file.cksum commands with a special device node such as /dev/urandom or /dev/zero. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P) 3.5 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:UR)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu Mar 13 2008 - 05:39:11 CDT Zabbix (zabbix_agentd) denial of service Source: MITRE Type: CNA CVE-2008-1353 Source: CCN Type: SA29383 ZABBIX "vfs.file.cksum" Denial of Service Vulnerability Source: SECUNIA Type: Vendor Advisory 29383 Source: SREASON Type: UNKNOWN 3747 Source: CCN Type: OSVDB ID: 42944 ZABBIX zabbix_agentd vfs.file.cksum Command Remote DoS Source: BUGTRAQ Type: UNKNOWN 20080313 Zabbix (zabbix_agentd) denial of service Source: BID Type: UNKNOWN 28244 Source: CCN Type: BID-28244 ZABBIX File Checksum Request Denial of Service Vulnerability Source: VUPEN Type: UNKNOWN ADV-2008-0878 Source: CCN Type: ZABBIX Web page Homepage of ZABBIX Source: CCN Type: ZABBIX Web site ZABBIX Source: XF Type: UNKNOWN zabbix-zabbixagentd-dos(41196) Source: XF Type: UNKNOWN zabbix-zabbixagentd-dos(41196) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |