CVE-2024-42328

When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allocated only in curl_write_cb when receiving data. If the server's response is an empty document, then wd->data in the code below will remain NULL and an attempt to read from it will result in a crash.
References
Link Resource
https://support.zabbix.com/browse/ZBX-25624 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*

History

08 Oct 2025, 16:42

Type Values Removed Values Added
First Time Zabbix
Zabbix zabbix
References () https://support.zabbix.com/browse/ZBX-25624 - () https://support.zabbix.com/browse/ZBX-25624 - Vendor Advisory
CPE cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*
Summary
  • (es) Cuando el controlador web del objeto Browser descarga datos de un servidor HTTP, el puntero de datos se establece en NULL y se asigna solo en curl_write_cb cuando se reciben datos. Si la respuesta del servidor es un documento vacío, entonces wd->data en el código a continuación permanecerá en NULL y un intento de leerlo provocará un bloqueo.

27 Nov 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-27 12:15

Updated : 2025-10-08 16:42


NVD link : CVE-2024-42328

Mitre link : CVE-2024-42328

CVE.ORG link : CVE-2024-42328


JSON object : View

Products Affected

zabbix

  • zabbix
CWE
CWE-476

NULL Pointer Dereference

CWE-690

Unchecked Return Value to NULL Pointer Dereference