Ad Widget

Collapse

Zabbix 3.0.31 and CVE-2020-11800

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • StackOverflow
    Junior Member
    • Nov 2015
    • 5

    #1

    Zabbix 3.0.31 and CVE-2020-11800

    Our security team recently reached out to me regarding CVE-2020-11800, which was addressed in ZBX-17600 with the fix being included in the 3.0.31rc. In looking at the notes for Zabbix 3.0.31, I see indicated fixes relating to Zabbix running in docker but no notes in the Zabbix issue. I was hoping to confirm if this was a docker specific issue or if it would indeed effect us running on RHEL?

    Thanks!
  • tim.mooney
    Senior Member
    • Dec 2012
    • 1427

    #2
    Based on how I read ZBX-17600 and the upgrade notes you've quoted, they are unrelated. The upgrade notes mention the docker-specific changes because they may impact people that were using 3.0.30 or earlier because of behavioral changes. People upgrading to 3.0.31 need to be aware of the docker change, because it may impact their environment.

    The ZBX-17600 fix doesn't get mentioned in the upgrade notes because it doesn't have any runtime impact on zabbix_server, but my reading is it's nothing specific to docker, it impacts any server environment (for the versions listed).

    The actual release notes ( https://www.zabbix.com/rn/rn3.0.31 ) mention the CVE, but don't actually mention the change related to docker, which is a bit weird. I would have expected a separate bug tracker ID for that change/enhancement.

    Seems like if you're planning on staying on the 3.0 LTS for a while yet, you might want to consider applying this upgrade to your server.

    Comment

    • StackOverflow
      Junior Member
      • Nov 2015
      • 5

      #3
      Originally posted by tim.mooney
      Based on how I read ZBX-17600 and the upgrade notes you've quoted, they are unrelated. The upgrade notes mention the docker-specific changes because they may impact people that were using 3.0.30 or earlier because of behavioral changes. People upgrading to 3.0.31 need to be aware of the docker change, because it may impact their environment.

      The ZBX-17600 fix doesn't get mentioned in the upgrade notes because it doesn't have any runtime impact on zabbix_server, but my reading is it's nothing specific to docker, it impacts any server environment (for the versions listed).

      The actual release notes ( https://www.zabbix.com/rn/rn3.0.31 ) mention the CVE, but don't actually mention the change related to docker, which is a bit weird. I would have expected a separate bug tracker ID for that change/enhancement.

      Seems like if you're planning on staying on the 3.0 LTS for a while yet, you might want to consider applying this upgrade to your server.
      Thanks Tim, I looked at the code changed in the commit history and indeed saw changes to some core functions for ipv6. I am going to begin investigating applying the upgrade to our environment, Thanks again!

      Comment

      • tim.mooney
        Senior Member
        • Dec 2012
        • 1427

        #4
        You're welcome!

        I looked at the diff too, and that's part of what made me fairly certain this was for any environment. Looks like they had a problem with parsing/identifying valid IPv6 addresses.

        Comment

        Working...