Red Hat Bugzilla – Bug 901875
CVE-2013-1364 zabbix: possible to override LDAP configuration parameters via the API
Last modified: 2014-03-31 01:10:05 EDT
It was reported  that the user.login method in Zabbix would accept a 'cnf' parameter containing the configuration parameters to use for LDAP authentication, which would override the configuration stored in the database. This can be used to authenticate to Zabbix using a completely different LDAP application (e.g. authenticate to Zabbix using some other LDAP directory the attacker has credentials for).
This has been corrected in upstream versions 2.1.0 r32446, 2.0.5rc1 r32444 and 1.8.16rc1 r32442. Patches are attached to the upstream bug report.
Created zabbix tracking bugs for this issue
Affects: epel-6 [bug 901876]
Affects: fedora-all [bug 901878]
Created zabbix20 tracking bugs for this issue
Affects: epel-6 [bug 901877]