CVE Vulnerabilities

CVE-2024-42328

NULL Pointer Dereference

Published: Nov 27, 2024 | Modified: Oct 08, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allocated only in curl_write_cb when receiving data. If the servers response is an empty document, then wd->data in the code below will remain NULL and an attempt to read from it will result in a crash.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Zabbix Zabbix 7.0.0 (including) 7.0.4 (excluding)
Zabbix Ubuntu focal *
Zabbix Ubuntu oracular *
Zabbix Ubuntu trusty/esm *

Potential Mitigations

References