CVE-2011-3263

Zabbix < 1.8.6 and 1.9.x < 1.9.4 - Denial of Service via vfs.file.cksum Command

Title source: llm
STIX 2.1

Description

zabbix_agentd in Zabbix before 1.8.6 and 1.9.x before 1.9.4 allows context-dependent attackers to cause a denial of service (CPU consumption) by executing the vfs.file.cksum command for a special device, as demonstrated by the /dev/urandom device.

References (3)

Core 3
Core References
Patch x_refsource_confirm
http://www.zabbix.com/rn1.8.6.php
Exploit x_refsource_confirm
https://support.zabbix.com/browse/ZBX-3794
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/69378

Scores

EPSS 0.0129
EPSS Percentile 67.1%

Details

CWE
CWE-399
Status published
Products (39)
zabbix/zabbix 1.1 (12 CPE variants)
zabbix/zabbix 1.1.1
zabbix/zabbix 1.1.2
zabbix/zabbix 1.1.3
zabbix/zabbix 1.1.4
zabbix/zabbix 1.1.5
zabbix/zabbix 1.1.6
zabbix/zabbix 1.1.7
zabbix/zabbix 1.3 beta
zabbix/zabbix 1.3.1 beta
... and 29 more
Published Aug 19, 2011
Tracked Since Feb 18, 2026