Ad Widget

Collapse

Zabbix 1.6.2 Frontend Multiple Vulnerabilities

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • vins
    Member
    • Feb 2009
    • 31

    #1

    Zabbix 1.6.2 Frontend Multiple Vulnerabilities

    20081215 Bug discovered
    20090116 Initial vendor contact
    20090116 Vendor Response (Fixes will be included in Zabbix 1.6.3)

    this bug was discovered in xmas and three months later we still with no workaround nor stable version...

    in these cases, we want to know as soon as possible when our systems are exposed to risk
  • vins
    Member
    • Feb 2009
    • 31

    #2
    when will we get an official response to this?

    Comment

    • swaterhouse
      Senior Member
      • Apr 2006
      • 268

      #3
      Not sure if this is the same one you were looking at but check this thread.

      Comment

      • vins
        Member
        • Feb 2009
        • 31

        #4
        yeah, it's the same, but "my" thread started one day before :P

        i suppose this issue is solved upgrading just frontend php files (agent and servers not affected, db schemes unaltered, etc) but i'm not 100% sure and i'm just asking for an official answer

        Comment

        • Alexei
          Founder, CEO
          Zabbix Certified Trainer
          Zabbix Certified SpecialistZabbix Certified Professional
          • Sep 2004
          • 5654

          #5
          The reported issues have been fixed several weeks ago. Scope of the changes is quite broad, so we decided not to release a patch before pre-1.6.3 testing is over. Please wait for official 1.6.3.

          Note that this affects PHP files only.
          Alexei Vladishev
          Creator of Zabbix, Product manager
          New York | Tokyo | Riga
          My Twitter

          Comment

          • vins
            Member
            • Feb 2009
            • 31

            #6
            thanks, alexei.

            i've upgraded only PHP frontend files to 1.6.3pre and it seems to work well (how nice the mouseover menus!).

            Comment

            • ashuji
              Member
              • Dec 2008
              • 35

              #7
              How to update

              Originally posted by vins
              thanks, alexei.

              i've upgraded only PHP frontend files to 1.6.3pre and it seems to work well (how nice the mouseover menus!).

              i also wanted to upgrade my zabbix installation to safegaurd from this vulnerability. It would be helpful for men and other zabbix users if you could paste here the procedure you followed for this upgrade.

              Thanks & regards

              Ashwani Jain

              Comment

              • vins
                Member
                • Feb 2009
                • 31

                #8
                download the tarball 1.6.3pre, uncompress it and copy frontend/php/* to your http directory. it's that simple.

                i also modified include/page_footer.php to hide ZABBIX_VER 'cause nobody needs to know which version am i running.

                Comment

                Working...