CVE-2012-6096
Nagios3 - 'history.cgi' Host Command Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
5Exploited in Wild
-Decision
Descriptions
Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1.8.4, might allow remote attackers to execute arbitrary code via a long (1) host_name variable (host parameter) or (2) svc_description variable.
Múltiples desbordamientos de búfer basado en pila en la función get_history en history.cgi en Nagios core anterior a v3.4.4, y Icinga v1.6.x anterior a v1.6.2, v1.7.x anterior a v1.7.4, y v1.8.x anterior a v1.8.4, permite a atacantes remotos ejecutar código de su elección a través de una variable (1) host_name de gran longitud o (2) de la variable svc_description.
Nagios version 3.x suffers from a remote command execution vulnerability in history.cgi.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-12-06 CVE Reserved
- 2013-01-13 First Exploit
- 2013-01-15 CVE Published
- 2024-08-06 CVE Updated
- 2024-10-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (18)
URL | Tag | Source |
---|---|---|
http://lists.grok.org.uk/pipermail/full-disclosure/2012-December/089125.html | Mailing List | |
http://www.nagios.org/projects/nagioscore/history/core-3x | X_refsource_confirm | |
http://www.osvdb.org/89170 | Vdb Entry | |
https://bugzilla.redhat.com/show_bug.cgi?id=893269 | X_refsource_confirm | |
https://www.icinga.org/2013/01/14/icinga-1-6-2-1-7-4-1-8-4-released | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/24159 | 2013-01-16 | |
https://www.exploit-db.com/exploits/24084 | 2013-01-13 | |
http://www.exploit-db.com/exploits/24084 | 2024-08-06 | |
http://www.exploit-db.com/exploits/24159 | 2024-08-06 | |
http://www.securityfocus.com/bid/56879 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-updates/2013-01/msg00033.html | 2013-06-05 | |
http://lists.opensuse.org/opensuse-updates/2013-01/msg00060.html | 2013-06-05 | |
http://lists.opensuse.org/opensuse-updates/2013-01/msg00077.html | 2013-06-05 | |
http://lists.opensuse.org/opensuse-updates/2013-01/msg00088.html | 2013-06-05 | |
http://secunia.com/advisories/51863 | 2013-06-05 | |
http://www.debian.org/security/2013/dsa-2616 | 2013-06-05 | |
http://www.debian.org/security/2013/dsa-2653 | 2013-06-05 | |
https://dev.icinga.org/issues/3532 | 2013-06-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | <= 3.4.3 Search vendor "Nagios" for product "Nagios" and version " <= 3.4.3" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | alpha1 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | alpha2 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | alpha3 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | alpha4 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | alpha5 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | beta1 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | beta2 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | beta3 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | beta4 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | beta5 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | beta6 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | beta7 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | rc1 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | rc2 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | rc3 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0.1 Search vendor "Nagios" for product "Nagios" and version "3.0.1" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0.2 Search vendor "Nagios" for product "Nagios" and version "3.0.2" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0.3 Search vendor "Nagios" for product "Nagios" and version "3.0.3" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0.4 Search vendor "Nagios" for product "Nagios" and version "3.0.4" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0.5 Search vendor "Nagios" for product "Nagios" and version "3.0.5" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0.6 Search vendor "Nagios" for product "Nagios" and version "3.0.6" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.1.0 Search vendor "Nagios" for product "Nagios" and version "3.1.0" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.1.1 Search vendor "Nagios" for product "Nagios" and version "3.1.1" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.1.2 Search vendor "Nagios" for product "Nagios" and version "3.1.2" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.2.0 Search vendor "Nagios" for product "Nagios" and version "3.2.0" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.2.1 Search vendor "Nagios" for product "Nagios" and version "3.2.1" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.2.2 Search vendor "Nagios" for product "Nagios" and version "3.2.2" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.2.3 Search vendor "Nagios" for product "Nagios" and version "3.2.3" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.3.1 Search vendor "Nagios" for product "Nagios" and version "3.3.1" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.4.0 Search vendor "Nagios" for product "Nagios" and version "3.4.0" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.4.1 Search vendor "Nagios" for product "Nagios" and version "3.4.1" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.4.2 Search vendor "Nagios" for product "Nagios" and version "3.4.2" | - |
Affected
| ||||||
Icinga Search vendor "Icinga" | Icinga Search vendor "Icinga" for product "Icinga" | 1.6.0 Search vendor "Icinga" for product "Icinga" and version "1.6.0" | - |
Affected
| ||||||
Icinga Search vendor "Icinga" | Icinga Search vendor "Icinga" for product "Icinga" | 1.6.1 Search vendor "Icinga" for product "Icinga" and version "1.6.1" | - |
Affected
| ||||||
Icinga Search vendor "Icinga" | Icinga Search vendor "Icinga" for product "Icinga" | 1.7.0 Search vendor "Icinga" for product "Icinga" and version "1.7.0" | - |
Affected
| ||||||
Icinga Search vendor "Icinga" | Icinga Search vendor "Icinga" for product "Icinga" | 1.7.1 Search vendor "Icinga" for product "Icinga" and version "1.7.1" | - |
Affected
| ||||||
Icinga Search vendor "Icinga" | Icinga Search vendor "Icinga" for product "Icinga" | 1.7.2 Search vendor "Icinga" for product "Icinga" and version "1.7.2" | - |
Affected
| ||||||
Icinga Search vendor "Icinga" | Icinga Search vendor "Icinga" for product "Icinga" | 1.7.3 Search vendor "Icinga" for product "Icinga" and version "1.7.3" | - |
Affected
| ||||||
Icinga Search vendor "Icinga" | Icinga Search vendor "Icinga" for product "Icinga" | 1.8.0 Search vendor "Icinga" for product "Icinga" and version "1.8.0" | - |
Affected
| ||||||
Icinga Search vendor "Icinga" | Icinga Search vendor "Icinga" for product "Icinga" | 1.8.1 Search vendor "Icinga" for product "Icinga" and version "1.8.1" | - |
Affected
| ||||||
Icinga Search vendor "Icinga" | Icinga Search vendor "Icinga" for product "Icinga" | 1.8.2 Search vendor "Icinga" for product "Icinga" and version "1.8.2" | - |
Affected
| ||||||
Icinga Search vendor "Icinga" | Icinga Search vendor "Icinga" for product "Icinga" | 1.8.3 Search vendor "Icinga" for product "Icinga" and version "1.8.3" | - |
Affected
|