CVE-2013-7108
Publication date 15 January 2014
Last updated 24 July 2024
Ubuntu priority
Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list to the process_cgivars function in (1) avail.c, (2) cmd.c, (3) config.c, (4) extinfo.c, (5) histogram.c, (6) notifications.c, (7) outages.c, (8) status.c, (9) statusmap.c, (10) summary.c, and (11) trends.c in cgi/, which triggers a heap-based buffer over-read.
Status
Package | Ubuntu Release | Status |
---|---|---|
icinga | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
nagios3 | ||
16.04 LTS xenial |
Fixed 3.5.1.dfsg-2.1ubuntu1.1
|
|
14.04 LTS trusty |
Fixed 3.5.1-1ubuntu1.1
|
|
Patch details
Package | Patch details |
---|---|
nagios3 |
References
Related Ubuntu Security Notices (USN)
- USN-3253-1
- Nagios vulnerabilities
- 3 April 2017