Home
MEDIUM: 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unknown
6.0.0 (git)
affected
7.0.0 (git)
affected
7.2.0 (git) before 7.2.1
affected
Description
Library loading on AIX Zabbix Agent builds can be hijacked by local users with write access to the /home/cecuser directory.
Problem types
CWE-426: Untrusted Search Path
Product status
6.0.0 (git)
7.0.0 (git)
7.2.0 (git) before 7.2.1
Credits
Zabbix wants to thank José Pina Coelho for finding and reporting this issue.
References
support.zabbix.com/browse/ZBX-27283