{"id":"CVE-2023-29451","details":"Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy.","modified":"2026-07-07T08:52:07.103637727Z","published":"2023-07-13T10:15:09.137Z","database_specific":{"unresolved_ranges":[{"source":"CPE_RANGE","vendor_product":"zabbix:zabbix","cpes":["cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"6.4.2"},{"last_affected":"6.4.4"}]},{"source":"CPE_STRING","vendor_product":"zabbix:zabbix","cpes":["cpe:2.3:a:zabbix:zabbix:6.4.0:alpha1:*:*:*:*:*:*","cpe:2.3:a:zabbix:zabbix:6.4.0:beta1:*:*:*:*:*:*","cpe:2.3:a:zabbix:zabbix:6.4.0:beta2:*:*:*:*:*:*","cpe:2.3:a:zabbix:zabbix:6.4.0:beta3:*:*:*:*:*:*","cpe:2.3:a:zabbix:zabbix:6.4.0:beta4:*:*:*:*:*:*","cpe:2.3:a:zabbix:zabbix:6.4.0:beta5:*:*:*:*:*:*","cpe:2.3:a:zabbix:zabbix:6.4.0:beta6:*:*:*:*:*:*","cpe:2.3:a:zabbix:zabbix:6.4.0:rc2:*:*:*:*:*:*","cpe:2.3:a:zabbix:zabbix:6.4.0:rc3:*:*:*:*:*:*","cpe:2.3:a:zabbix:zabbix:6.4.0:rc4:*:*:*:*:*:*"],"extracted_events":[{"introduced":"6.4.0-alpha1"},{"last_affected":"6.4.0-alpha1"},{"introduced":"6.4.0-beta1"},{"last_affected":"6.4.0-beta1"},{"introduced":"6.4.0-beta2"},{"last_affected":"6.4.0-beta2"},{"introduced":"6.4.0-beta3"},{"last_affected":"6.4.0-beta3"},{"introduced":"6.4.0-beta4"},{"last_affected":"6.4.0-beta4"},{"introduced":"6.4.0-beta5"},{"last_affected":"6.4.0-beta5"},{"introduced":"6.4.0-beta6"},{"last_affected":"6.4.0-beta6"},{"introduced":"6.4.0-rc2"},{"last_affected":"6.4.0-rc2"},{"introduced":"6.4.0-rc3"},{"last_affected":"6.4.0-rc3"},{"introduced":"6.4.0-rc4"},{"last_affected":"6.4.0-rc4"}]}]},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/08/msg00027.html"},{"type":"ADVISORY","url":"https://support.zabbix.com/browse/ZBX-22587"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zabbix/zabbix","events":[{"introduced":"0"},{"last_affected":"3f184b456c78eb8c0ecdac62d708e38e1b1eba68"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"6.0.14"}]}}],"versions":["6.0.14","6.0.14rc2","6.0.14rc1","6.0.13","6.0.13rc1","6.0.12","6.0.12rc2","6.0.12rc1","6.0.11","6.0.11rc2","6.0.11rc1","6.0.10rc1","6.0.10","6.0.10rc2","6.0.9","6.0.9rc2","6.0.9rc1","6.0.8","6.0.8rc2","6.0.8rc1","6.0.7","6.0.1","6.0.7rc1","6.0.6","6.0.6rc1","6.0.5","6.0.5rc1","6.0.4","6.0.4rc1","6.0.3","6.0.3rc1","6.0.2","6.0.2rc1","6.0.1rc4","6.0.1rc3","6.0.1rc2","6.0.1rc1","6.0.0","6.0.0rc2","6.0.0rc1","6.0.0beta3","6.0.0beta2","6.0.0beta1","6.0.0alpha7","6.0.0alpha6","6.0.0alpha5","6.0.0alpha4","6.0.0alpha3","6.0.0alpha2","6.0.0alpha1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-29451.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}