Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.rc > #400531 > unrolled thread

Bug#1117448: zabbix: CVE-2025-49641 CVE-2025-27238 CVE-2025-27236 CVE-2025-27233 CVE-2025-27231

Started bySalvatore Bonaccorso <carnil@debian.org>
First post2025-10-05 21:30 +0200
Last post2026-01-24 03:40 +0100
Articles 2 — 2 participants

Back to article view | Back to linux.debian.bugs.rc


Contents

  Bug#1117448: zabbix: CVE-2025-49641 CVE-2025-27238 CVE-2025-27236 CVE-2025-27233 CVE-2025-27231 Salvatore Bonaccorso <carnil@debian.org> - 2025-10-05 21:30 +0200
    Bug#1117448: marked as done (zabbix: CVE-2025-49641  CVE-2025-27238 CVE-2025-27236 CVE-2025-27233 CVE-2025-27231) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2026-01-24 03:40 +0100

#400531 — Bug#1117448: zabbix: CVE-2025-49641 CVE-2025-27238 CVE-2025-27236 CVE-2025-27233 CVE-2025-27231

FromSalvatore Bonaccorso <carnil@debian.org>
Date2025-10-05 21:30 +0200
SubjectBug#1117448: zabbix: CVE-2025-49641 CVE-2025-27238 CVE-2025-27236 CVE-2025-27233 CVE-2025-27231
Message-ID<LCCAF-304J-3@gated-at.bofh.it>
Source: zabbix
Version: 1:7.0.10+dfsg-2
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>

Hi,

The following vulnerabilities were published for zabbix.

CVE-2025-49641[0]:
| A regular Zabbix user with no permission to the Monitoring ->
| Problems view is still able to call the problem.view.refresh action
| and therefore still retrieve a list of active problems.


CVE-2025-27238[1]:
| Due to a bug in Zabbix API, the hostprototype.get method lists all
| host prototypes to users that do not have any user groups assigned
| to them.


CVE-2025-27236[2]:
| A regular Zabbix user can search other users in their user group via
| Zabbix API by select fields the user does not have access to view.
| This allows data-mining some field values the user does not have
| access to.


CVE-2025-27233[3]:
| Zabbix Agent 2 smartctl plugin does not properly sanitize
| smart.disk.get parameters, allowing an attacker to inject unexpected
| arguments into the smartctl command. This can be used to leak the
| NTLMv2 hash from a Windows system.


CVE-2025-27231[4]:
| The LDAP 'Bind password' value cannot be read after saving, but a
| Super Admin account can leak it by changing LDAP 'Host' to a rogue
| LDAP server. To mitigate this, the 'Bind password' value is now
| reset on 'Host' change.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-49641
    https://www.cve.org/CVERecord?id=CVE-2025-49641
[1] https://security-tracker.debian.org/tracker/CVE-2025-27238
    https://www.cve.org/CVERecord?id=CVE-2025-27238
[2] https://security-tracker.debian.org/tracker/CVE-2025-27236
    https://www.cve.org/CVERecord?id=CVE-2025-27236
[3] https://security-tracker.debian.org/tracker/CVE-2025-27233
    https://www.cve.org/CVERecord?id=CVE-2025-27233
[4] https://security-tracker.debian.org/tracker/CVE-2025-27231
    https://www.cve.org/CVERecord?id=CVE-2025-27231

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

[toc] | [next] | [standalone]


#409784 — Bug#1117448: marked as done (zabbix: CVE-2025-49641 CVE-2025-27238 CVE-2025-27236 CVE-2025-27233 CVE-2025-27231)

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2026-01-24 03:40 +0100
SubjectBug#1117448: marked as done (zabbix: CVE-2025-49641 CVE-2025-27238 CVE-2025-27236 CVE-2025-27233 CVE-2025-27231)
Message-ID<MgBJ8-cOZC-9@gated-at.bofh.it>
In reply to#400531

[Multipart message — attachments visible in raw view] — view raw

Your message dated Sat, 24 Jan 2026 02:35:06 +0000
with message-id <E1vjTUQ-0000000H91a-3pOw@fasolo.debian.org>
and subject line Bug#1117448: fixed in zabbix 1:7.0.22+dfsg-1
has caused the Debian Bug report #1117448,
regarding zabbix: CVE-2025-49641 CVE-2025-27238 CVE-2025-27236 CVE-2025-27233 CVE-2025-27231
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
1117448: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117448
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.rc


csiph-web