bugs.debian.orgConfirmation
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=452682 CVE-2007-6210
Zabbix 1.1.4/1.4.2 - 'daemon_start' Local Privilege Escalation
Record summary
CVE-2007-6210 has a selected CVSS score of 2.1; EIP currently links 1 catalogued exploit.
Description
zabbix_agentd 1.1.4 in ZABBIX before 1.4.3 runs "UserParameter" scripts with gid 0, which might allow local users to gain privileges.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBZabbix 1.1.4/1.4.2 - 'daemon_start' Local Privilege EscalationExploitDB exploitby Bas van SchaikNot analyzed1 file
References
1027903Third-party advisory
http://secunia.com/advisories/27903 27948Third-party advisory
http://secunia.com/advisories/27948 27978Third-party advisory
http://secunia.com/advisories/27978 DSA-1420Vendor advisory
http://www.debian.org/security/2007/dsa-1420 26680vdb entry
http://www.securityfocus.com/bid/26680 zabbix.comConfirmation
http://www.zabbix.com/forum/showthread.php?t=8400 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-6210 FEDORA-2007-4160Vendor advisory
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00196.html FEDORA-2007-4176Vendor advisory
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00232.html