CVE-2013-7205
Mandriva Linux Security Advisory 2014-004
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Off-by-one error in the process_cgivars function in contrib/daemonchk.c in Nagios Core 3.5.1, 4.0.2, and earlier allows remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list, which triggers a heap-based buffer over-read.
Error de superación de límite (off-by-one) en la función process_cgivars en contrib/daemonchk.c en Nagios Core 3.5.1, 4.0.2 y anteriores, permite a usuarios autenticados remotamente obtener información sensible desde procesos de memoria o causar denegación de servicio (caída) a través de cadenas largas en el valor de la última clave en la lista de variables, lo cual lanza una sobre-lectura de buffer basada en memoria dinámica.
Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information from process memory or cause a denial of service via a long string in the last key value in the variable list to the process_cgivars function in extinfo.c, status.c, trends.c in cgi/, which triggers a heap-based buffer over-read. Off-by-one error in the process_cgivars function in contrib/daemonchk.c in Nagios Core 3.5.1, 4.0.2, and earlier allows remote authenticated users to obtain sensitive information from process memory or cause a denial of service via a long string in the last key value in the variable list, which triggers a heap-based buffer over-read. The updated packages have been patched to correct these issues.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-12-23 CVE Reserved
- 2014-01-14 CVE Published
- 2024-08-06 CVE Updated
- 2025-04-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://sourceforge.net/p/nagios/nagioscore/ci/d97e03f32741a7d851826b03ed73ff4c9612a866 | X_refsource_confirm | |
http://www.openwall.com/lists/oss-security/2013/12/24/1 | Mailing List |
|
http://www.securityfocus.com/bid/64489 | Vdb Entry | |
https://lists.debian.org/debian-lts-announce/2018/12/msg00014.html | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/55976 | 2018-12-25 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2014:004 | 2018-12-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | <= 4.0.2 Search vendor "Nagios" for product "Nagios" and version " <= 4.0.2" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | alpha1 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | alpha2 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | alpha3 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | alpha4 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | alpha5 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | beta1 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | beta2 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | beta3 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | beta4 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | beta5 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | beta6 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | beta7 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | rc1 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | rc2 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0 Search vendor "Nagios" for product "Nagios" and version "3.0" | rc3 |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0.1 Search vendor "Nagios" for product "Nagios" and version "3.0.1" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0.2 Search vendor "Nagios" for product "Nagios" and version "3.0.2" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0.3 Search vendor "Nagios" for product "Nagios" and version "3.0.3" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0.4 Search vendor "Nagios" for product "Nagios" and version "3.0.4" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0.5 Search vendor "Nagios" for product "Nagios" and version "3.0.5" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.0.6 Search vendor "Nagios" for product "Nagios" and version "3.0.6" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.1.0 Search vendor "Nagios" for product "Nagios" and version "3.1.0" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.1.1 Search vendor "Nagios" for product "Nagios" and version "3.1.1" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.1.2 Search vendor "Nagios" for product "Nagios" and version "3.1.2" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.2.0 Search vendor "Nagios" for product "Nagios" and version "3.2.0" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.2.1 Search vendor "Nagios" for product "Nagios" and version "3.2.1" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.2.2 Search vendor "Nagios" for product "Nagios" and version "3.2.2" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.2.3 Search vendor "Nagios" for product "Nagios" and version "3.2.3" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.3.1 Search vendor "Nagios" for product "Nagios" and version "3.3.1" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.4.0 Search vendor "Nagios" for product "Nagios" and version "3.4.0" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.4.1 Search vendor "Nagios" for product "Nagios" and version "3.4.1" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.4.2 Search vendor "Nagios" for product "Nagios" and version "3.4.2" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.4.3 Search vendor "Nagios" for product "Nagios" and version "3.4.3" | - |
Affected
| ||||||
Nagios Search vendor "Nagios" | Nagios Search vendor "Nagios" for product "Nagios" | 3.5.1 Search vendor "Nagios" for product "Nagios" and version "3.5.1" | - |
Affected
|