12 February 2014

Zabbix SIA is proud to announce the availability of Zabbix 1.8.20.

Zabbix is an enterprise-class open source distributed monitoring solution. Zabbix is released under the GPL, thus it is free of charge for both commercial and non-commercial use. A complete text of the license is available at

This document contains the release notes for Zabbix 1.8.20. Download it from

This release fixes known issues of Zabbix 1.8.x. A nice overview of the new functionality is available at

This release contains security fixes for CVE-2014-1685, CVE-2014-1682 and CVE-2013-5572. Please read below for more details.

If you are using Zabbix 1.8 with node-based distributed setup, please run the following SQL patch. It should improve performance of configuration syncing a lot.

DROP INDEX node_cksum_1 ON node_cksum;
CREATE INDEX node_cksum_1 on node_cksum (nodeid,cksumtype,tablename,recordid);

DROP INDEX node_cksum_1;
CREATE INDEX node_cksum_1 on node_cksum (nodeid,cksumtype,tablename,recordid);

DROP INDEX node_cksum_1;
CREATE INDEX node_cksum_1 on node_cksum (nodeid,cksumtype,tablename,recordid);

The following sections describe the release in details and provide late-breaking or other information that supplements its main documentation.

What's New in 1.8.20

:: Security fixes

  • [ZBX-7703] fixed being able to switch users without proper credentials when using HTTP authentication; reference CVE-2014-1682
  • [ZBX-7693] fixed admin user being able to update media for other users; reference CVE-2014-1685
  • [ZBX-6721] fixed LDAP authentication; reference CVE-2013-5572

:: Complete List of Bug Fixes and Improvements included into 1.8.20

  • [ZBX-7693] fixed admin user being able to update media for other users
  • [ZBX-6721] fixed LDAP authentication
  • [ZBX-7703] fixed being able to switch users without proper credentials when using HTTP authentication
  • [ZBX-7686] fixed UTF-8 strings not being fetched fully from Oracle
  • [ZBX-7643] fixed graph copying
  • [ZBX-3702] fixed drule.get selectDChecks parameter not returning any results; thanks to Sergey Sireskin
  • [ZBX-4243] fixed Zabbix syslog application names (RFC 5424 APP-NAME)

Installation and Upgrade Notes


See Zabbix Manual for full details.


Recompile Zabbix binaries and update front-end PHP files. Execute a database patch if migrating from Zabbix 1.6.x. See Zabbix Manual for a detailed upgrade procedure.

Pre-release testing

Zabbix Server

Zabbix Server has been tested on the following platforms:

  • Ubuntu Linux, AMD64, kernel 2.6.11, MySQL 5.x
  • Ubuntu Linux, Intel, kernel 2.6.15, MySQL 5.0.22, PostgreSQL 8.3
  • RedHat EL 5.3, Intel, kernel 2.6.18, Oracle 11gR2
  • Slackware Linux, x86, kernel, MySQL 5.1.x

Zabbix Agents

Zabbix Agents have been compiled and tested on the following platforms:

  • AIX 5.2
  • FreeBSD 4.x, 5.x, 6.x
  • HP-UX 10.x, 11.x
  • Linux 2.4.x, 2.6.x
  • Linux CentOS
  • NetBSD 2.0
  • OS/X 10.2
  • Solaris 8, 9, 10
  • Tru64 5.1B
  • Windows 2000, Server 2003, XP, Vista, Server 2008, 7, 8, Server 2012

Note that agents are available pre-compiled from for a limited number of versions and platforms.

Commercial support

Zabbix Company provides a full range of professional services. We also provide trouble-free upgrade service for easy migration from earlier versions to Zabbix 1.8.x. Please contact Sales for pricing and more details.


