Candidate: CVE-2014-1685 PublicDate: 2014-05-08 14:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1685 https://support.zabbix.com/browse/ZBX-7693 http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132377.html http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132376.html Description: The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x before 2.2.2rc1 allows remote "Zabbix Admin" users to modify the media of arbitrary users via unspecified vectors. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Corey Shaw Assigned-to: CVSS: Patches_zabbix: upstream_zabbix: released (1:2.2.2+dfsg-1) lucid_zabbix: ignored (reached end-of-life) precise_zabbix: ignored (reached end-of-life) precise/esm_zabbix: DNE (precise was needed) quantal_zabbix: ignored (reached end-of-life) saucy_zabbix: ignored (reached end-of-life) trusty_zabbix: not-affected (1:2.2.2+dfsg-1ubuntu1) trusty/esm_zabbix: not-affected (1:2.2.2+dfsg-1ubuntu1) utopic_zabbix: not-affected vivid_zabbix: not-affected vivid/stable-phone-overlay_zabbix: DNE vivid/ubuntu-core_zabbix: DNE wily_zabbix: not-affected xenial_zabbix: not-affected yakkety_zabbix: not-affected zesty_zabbix: not-affected devel_zabbix: not-affected