CVE Vulnerabilities

CVE-2024-42328

NULL Pointer Dereference

Published: Nov 27, 2024 | Modified: Nov 27, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allocated only in curl_write_cb when receiving data. If the servers response is an empty document, then wd->data in the code below will remain NULL and an attempt to read from it will result in a crash.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Zabbix Ubuntu trusty/esm *

Potential Mitigations

References