← Back

CVE-2024-42328

nvd nist
Published: Nov 27, 2024Modified: Jun 17, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allocated only in curl_write_cb when receiving data. If the server's response is an empty document, then wd->data in the code below will remain NULL and an attempt to read from it will result in a crash.

Affected (1)

Products: Zabbix: Zabbix
1 product
Zabbix
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 7.0.0 to 7.0.4

References (1)

Source: security@zabbix.com
Vendor Advisory

Timeline

No history available yet.