Stack-based buffer overflow in the cmd_submitf function in cgi/cmd.c in Nagios Core, possibly 4.0.3rc1 and earlier, and Icinga before 1.8.6, 1.9 before 1.9.5, and 1.10 before 1.10.3 allows remote attackers to cause a denial of service (segmentation fault) via a long message to cmd.cgi.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:05
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-updates/2014-04/msg00033.html - | |
References | () http://secunia.com/advisories/57024 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/65605 - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=1066578 - | |
References | () https://dev.icinga.org/issues/5434 - Patch | |
References | () https://lists.debian.org/debian-lts-announce/2018/12/msg00014.html - | |
References | () https://www.icinga.org/2014/02/11/bugfix-releases-1-10-3-1-9-5-1-8-6 - |
Information
Published : 2014-02-28 15:13
Updated : 2024-11-21 02:05
NVD link : CVE-2014-1878
Mitre link : CVE-2014-1878
CVE.ORG link : CVE-2014-1878
JSON object : View
Products Affected
icinga
- icinga
nagios
- nagios
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer