PT-2024-6101 · Zabbix+4 · Zabbix+4

Pavel Voit

+1

·

Published

2024-08-09

·

Updated

2024-12-10

·

CVE-2024-36461

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Zabbix versions 6.0.30 through 6.0.30, 6.4.15, and 7.0.0
Description The issue is related to the ability to directly modify memory pointers in the JavaScript engine within Zabbix. This could allow a remote attacker to execute arbitrary code.
Recommendations For Zabbix versions 6.0.30, 6.4.15, and 7.0.0, upgrade to newer versions, such as 6.0.31rc1, 6.4.16rc1, or 7.0.1rc1, respectively, to safeguard resources.

Fix

Untrusted Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2024-11575
ALT-PU-2024-15832
BDU:2024-07010
CVE-2024-36461
DLA-3909-1
OPENSUSE-SU-2024:0384-1
OPENSUSE-SU-2024:14356-1

Affected Products

Alt Linux
Astra Linux
Debian
Red Os
Zabbix