CVE-2012-6086

libs/zbxmedia/eztexting.c in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.8rc1, and 2.1.x before 2.1.2 does not properly set the CURLOPT_SSL_VERIFYHOST option for libcurl, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 41%
VendorProductVersion
zabbixzabbix
1.8.1
zabbixzabbix
1.8.10:rc1
zabbixzabbix
1.8.10:rc2
zabbixzabbix
1.8.15:rc1
zabbixzabbix
1.8.16
zabbixzabbix
2.0.0
zabbixzabbix
2.0.0:rc1
zabbixzabbix
2.0.0:rc2
zabbixzabbix
2.0.0:rc3
zabbixzabbix
2.0.0:rc4
zabbixzabbix
2.0.0:rc5
zabbixzabbix
2.0.0:rc6
zabbixzabbix
2.0.1
zabbixzabbix
2.0.1:rc1
zabbixzabbix
2.0.1:rc2
zabbixzabbix
2.0.2
zabbixzabbix
2.0.3
zabbixzabbix
2.0.4
zabbixzabbix
2.0.5
zabbixzabbix
2.0.6
zabbixzabbix
2.1.0
zabbixzabbix
2.1.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
zabbix
bullseye
1:5.0.8+dfsg-1
fixed
squeeze
no-dsa
bullseye (security)
1:5.0.44+dfsg-1+deb11u1
fixed
bookworm
1:6.0.14+dfsg-1
fixed
sid
1:7.0.5+dfsg-1
fixed
trixie
1:7.0.5+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
zabbix
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
not-affected
saucy
ignored
raring
ignored
quantal
ignored
precise
ignored
oneiric
ignored
lucid
ignored
hardy
ignored
Common Weakness Enumeration