zabbix_agentd in Zabbix before 1.8.6 and 1.9.x before 1.9.4 allows context-dependent attackers to cause a denial of service (CPU consumption) by executing the vfs.file.cksum command for a special device, as demonstrated by the /dev/urandom device.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://www.zabbix.com/rn1.8.6.php | patch |
https://support.zabbix.com/browse/ZBX-3794 | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/69378 | vdb entry |