zabbix_agentd 1.1.4 in ZABBIX before 1.4.3 runs "UserParameter" scripts with gid 0, which might allow local users to gain privileges.
Weaknesses in this category are typically introduced during the configuration of the software.
Link | Tags |
---|---|
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00196.html | vendor advisory |
http://www.debian.org/security/2007/dsa-1420 | vendor advisory |
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00232.html | vendor advisory |
http://secunia.com/advisories/27903 | third party advisory |
http://www.zabbix.com/forum/showthread.php?t=8400 | |
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=452682 | patch |
http://secunia.com/advisories/27948 | third party advisory |
http://secunia.com/advisories/27978 | third party advisory |
http://www.securityfocus.com/bid/26680 | vdb entry |