Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2009-4502
HistoryOct 03, 2022 - 4:24 p.m.

CVE-2009-4502

2022-10-0316:24:04
Debian Security Bug Tracker
security-tracker.debian.org
7
zabbix agent
net_tcp_listen
vulnerability
freebsd
solaris
remote attackers
enableremotecommands
arbitrary commands
shell metacharacters
trusted ip addresses

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

0.928 High

EPSS

Percentile

99.0%

The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass the EnableRemoteCommands setting and execute arbitrary commands via shell metacharacters in the argument to net.tcp.listen. NOTE: this attack is limited to attacks from trusted IP addresses.

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

0.928 High

EPSS

Percentile

99.0%

Related for DEBIANCVE:CVE-2009-4502