CVE-2012-6086 Information
Feb 14, 2021
cve
Description
libs/zbxmedia/eztexting.c in Zabbix 1.8.x before 1.8.18rc1 2.0.x before 2.0.8rc1 and 2.1.x before 2.1.2 does not properly set the CURLOPT_SSL_VERIFYHOST option for libcurl which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Reference
http://www.openwall.com/lists/oss-security/2013/01/03/1 [oss-security] 20130103 Re: CVE request: Curl insecure usage http://www.securityfocus.com/bid/57103 https://support.zabbix.com/browse/ZBX-5924 libs/zbxmedia/eztexting.c in Zabbix 1.8.x before 1.8.18rc1 2.0.x before 2.0.8rc1 and 2.1.x before 2.1.2 does not properly set the CURLOPT_SSL_VERIFYHOST option for libcurl which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Share on: