Description: A weakness has been reported in Zabbix, which can be exploited by malicious users to perform certain actions with escalated privileges.
The weakness is caused due to the "daemon_start()" function in src/libs/zbxnix/daemon.c not correctly dropping the privileges. This can be exploited to e.g. execute "UserParameter" scripts as group "root".
This affects the agent for UNIX-like operating systems only.
The weakness is reported in version 1.4.2. Other versions may also be affected.
Solution: Update to version 1.4.3.
Provided and/or discovered by: Bas van Schaik
Changelog: 2007-12-04: Added CVE reference.
2007-12-12: Updated "Solution" section.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.