PT-2024-9611 · Zabbix+3 · Zabbix+3

Vjaceslavs Bogdanovs

·

Published

2024-11-27

·

Updated

2025-10-08

·

CVE-2024-42328

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Browser object (affected versions not specified) Zabbix (affected versions not specified)
Description The issue is related to the handling of data downloaded from an HTTP server by the Browser object's web driver. When the server's response is an empty document, the data pointer remains NULL, and attempting to read from it results in a crash. This is due to the curl write cb function not allocating the data pointer until data is received. The vulnerability can be exploited to cause a denial of service (DoS).
Recommendations For the Browser object, consider implementing a check to ensure the data pointer is not NULL before attempting to read from it. For Zabbix, as a temporary workaround, consider restricting access to the curl write cb function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2024-16527
ALT-PU-2024-16638
BDU:2024-11323
CVE-2024-42328

Affected Products

Alt Linux
Astra Linux
Red Os
Zabbix