Ad Widget

Collapse

Please feature security fixes more prominently in your announcements

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • TuXator
    Junior Member
    • Feb 2009
    • 15

    #1

    Please feature security fixes more prominently in your announcements

    Hi!

    I just noticed, that 1.6.7 fixes an important security vulnerability.
    Unfortunately the announcement only promotes an agent fix concerning active checks. The note about the security fix can only be found in the "fine print" way below under "Other Improvements and Bug Fixes":

    http://www.zabbix.com/rn1.6.7.php
    * [ZBX-1031] fixed security vulnerability in server, allowing remote unauthenticated users to execute arbitrary SQL queries. Thanks to Nicob
    # [ZBX-1032] fixed security vulnerability in processing of net.tcp.listen under FreeBSD and Solaris agents. Thanks to Nicob
    I believe that such important issues should be pointed out more clearly!

    Other examples:

    Cheers,
    --leo
  • Alexei
    Founder, CEO
    Zabbix Certified Trainer
    Zabbix Certified SpecialistZabbix Certified Professional
    • Sep 2004
    • 5654

    #2
    Originally posted by TuXator
    I believe that such important issues should be pointed out more clearly!
    You are absolutely right, security-related issues must be emphasized the in release notes. It is something to improve in future releases!
    Alexei Vladishev
    Creator of Zabbix, Product manager
    New York | Tokyo | Riga
    My Twitter

    Comment

    Working...