CVE-2023-32726

The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zabbix:zabbix-agent:*:*:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix-agent:*:*:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix-agent:*:*:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix-agent:7.0.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix-agent:7.0.0:alpha6:*:*:*:*:*:*

History

24 Jan 2024, 22:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/01/msg00012.html -

17 Jan 2024, 04:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BYSYLA7VTHR25CBLYO5ZLEJFGU7HTHQB/ -

17 Jan 2024, 03:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UMFKNV5E4LG2DIZNPRWQ2ENH75H6UEQT/ -

22 Dec 2023, 21:11

Type Values Removed Values Added
References () https://support.zabbix.com/browse/ZBX-23855 - () https://support.zabbix.com/browse/ZBX-23855 - Vendor Advisory
Summary
  • (es) La vulnerabilidad se debe a una verificación incorrecta de si RDLENGTH no desborda el búfer en respuesta del servidor DNS.
CVSS v2 : unknown
v3 : 3.9
v2 : unknown
v3 : 8.1
First Time Zabbix zabbix-agent
Zabbix
CPE cpe:2.3:a:zabbix:zabbix-agent:*:*:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix-agent:7.0.0:alpha6:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix-agent:7.0.0:alpha1:*:*:*:*:*:*

18 Dec 2023, 14:05

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-18 10:15

Updated : 2024-01-24 22:15


NVD link : CVE-2023-32726

Mitre link : CVE-2023-32726

CVE.ORG link : CVE-2023-32726


JSON object : View

Products Affected

zabbix

  • zabbix-agent
CWE
CWE-754

Improper Check for Unusual or Exceptional Conditions