Ad Widget

Collapse

ZBX-1030 for 1.6.x?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • js1
    Member
    • Apr 2009
    • 66

    #1

    ZBX-1030 for 1.6.x?

    Has the vulnerability described in ZBX-1030 been addressed in 1.6.8? Or, is it only fixed in 1.8?
  • Alexei
    Founder, CEO
    Zabbix Certified Trainer
    Zabbix Certified SpecialistZabbix Certified Professional
    • Sep 2004
    • 5654

    #2
    It is only fixed in 1.8. The problem is that the fix requires changes in communication protocol between the front-end and the server. This would break compatibility with earlier versions of 1.6.x.
    Alexei Vladishev
    Creator of Zabbix, Product manager
    New York | Tokyo | Riga
    My Twitter

    Comment

    • js1
      Member
      • Apr 2009
      • 66

      #3
      Originally posted by Alexei
      It is only fixed in 1.8. The problem is that the fix requires changes in communication protocol between the front-end and the server. This would break compatibility with earlier versions of 1.6.x.
      What is recommended for mitigating the risks to 1.6.x deployments?

      Comment

      • Alexei
        Founder, CEO
        Zabbix Certified Trainer
        Zabbix Certified SpecialistZabbix Certified Professional
        • Sep 2004
        • 5654

        #4
        Actually it WILL be integrated into 1.6.x!

        The integration is quite straight-forward, the only drawback is that once it is fixed one should use latest revisions of both front-end and Zabbix server, which is probably what most users already do.
        Alexei Vladishev
        Creator of Zabbix, Product manager
        New York | Tokyo | Riga
        My Twitter

        Comment

        • js1
          Member
          • Apr 2009
          • 66

          #5
          Originally posted by Alexei
          Actually it WILL be integrated into 1.6.x!

          The integration is quite straight-forward, the only drawback is that once it is fixed one should use latest revisions of both front-end and Zabbix server, which is probably what most users already do.
          Sounds good. Looking forward to the fix.

          Comment

          Working...