CVE Vulnerabilities

CVE-2012-6086

Published: Jan 29, 2014 | Modified: Aug 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

libs/zbxmedia/eztexting.c in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.8rc1, and 2.1.x before 2.1.2 does not properly set the CURLOPT_SSL_VERIFYHOST option for libcurl, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Affected Software

Name Vendor Start Version End Version
Zabbix Zabbix 1.8.1 (including) 1.8.1 (including)
Zabbix Zabbix 1.8.10-rc1 (including) 1.8.10-rc1 (including)
Zabbix Zabbix 1.8.10-rc2 (including) 1.8.10-rc2 (including)
Zabbix Zabbix 1.8.15-rc1 (including) 1.8.15-rc1 (including)
Zabbix Zabbix 1.8.16 (including) 1.8.16 (including)
Zabbix Zabbix 2.0.0 (including) 2.0.0 (including)
Zabbix Zabbix 2.0.0-rc1 (including) 2.0.0-rc1 (including)
Zabbix Zabbix 2.0.0-rc2 (including) 2.0.0-rc2 (including)
Zabbix Zabbix 2.0.0-rc3 (including) 2.0.0-rc3 (including)
Zabbix Zabbix 2.0.0-rc4 (including) 2.0.0-rc4 (including)
Zabbix Zabbix 2.0.0-rc5 (including) 2.0.0-rc5 (including)
Zabbix Zabbix 2.0.0-rc6 (including) 2.0.0-rc6 (including)
Zabbix Zabbix 2.0.1 (including) 2.0.1 (including)
Zabbix Zabbix 2.0.1-rc1 (including) 2.0.1-rc1 (including)
Zabbix Zabbix 2.0.1-rc2 (including) 2.0.1-rc2 (including)
Zabbix Zabbix 2.0.2 (including) 2.0.2 (including)
Zabbix Zabbix 2.0.3 (including) 2.0.3 (including)
Zabbix Zabbix 2.0.4 (including) 2.0.4 (including)
Zabbix Zabbix 2.0.5 (including) 2.0.5 (including)
Zabbix Zabbix 2.0.6 (including) 2.0.6 (including)
Zabbix Zabbix 2.1.0 (including) 2.1.0 (including)
Zabbix Zabbix 2.1.1 (including) 2.1.1 (including)
Zabbix Ubuntu hardy *
Zabbix Ubuntu lucid *
Zabbix Ubuntu oneiric *
Zabbix Ubuntu precise *
Zabbix Ubuntu quantal *
Zabbix Ubuntu raring *
Zabbix Ubuntu saucy *
Zabbix Ubuntu upstream *

References