Lucene search

K
cve[email protected]CVE-2013-7205
HistoryJan 15, 2014 - 4:08 p.m.

CVE-2013-7205

2014-01-1516:08:04
CWE-119
web.nvd.nist.gov
40
cve-2013-7205
nagios core
off-by-one error
remote authenticated users
heap-based buffer over-read
security vulnerability

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:N/A:P

7.2 High

AI Score

Confidence

High

0.018 Low

EPSS

Percentile

88.0%

Off-by-one error in the process_cgivars function in contrib/daemonchk.c in Nagios Core 3.5.1, 4.0.2, and earlier allows remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list, which triggers a heap-based buffer over-read.

Affected configurations

NVD
Node
nagiosnagiosRange4.0.2
OR
nagiosnagiosMatch3.0
OR
nagiosnagiosMatch3.0alpha1
OR
nagiosnagiosMatch3.0alpha2
OR
nagiosnagiosMatch3.0alpha3
OR
nagiosnagiosMatch3.0alpha4
OR
nagiosnagiosMatch3.0alpha5
OR
nagiosnagiosMatch3.0beta1
OR
nagiosnagiosMatch3.0beta2
OR
nagiosnagiosMatch3.0beta3
OR
nagiosnagiosMatch3.0beta4
OR
nagiosnagiosMatch3.0beta5
OR
nagiosnagiosMatch3.0beta6
OR
nagiosnagiosMatch3.0beta7
OR
nagiosnagiosMatch3.0rc1
OR
nagiosnagiosMatch3.0rc2
OR
nagiosnagiosMatch3.0rc3
OR
nagiosnagiosMatch3.0.1
OR
nagiosnagiosMatch3.0.2
OR
nagiosnagiosMatch3.0.3
OR
nagiosnagiosMatch3.0.4
OR
nagiosnagiosMatch3.0.5
OR
nagiosnagiosMatch3.0.6
OR
nagiosnagiosMatch3.1.0
OR
nagiosnagiosMatch3.1.1
OR
nagiosnagiosMatch3.1.2
OR
nagiosnagiosMatch3.2.0
OR
nagiosnagiosMatch3.2.1
OR
nagiosnagiosMatch3.2.2
OR
nagiosnagiosMatch3.2.3
OR
nagiosnagiosMatch3.3.1
OR
nagiosnagiosMatch3.4.0
OR
nagiosnagiosMatch3.4.1
OR
nagiosnagiosMatch3.4.2
OR
nagiosnagiosMatch3.4.3
OR
nagiosnagiosMatch3.5.1

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:N/A:P

7.2 High

AI Score

Confidence

High

0.018 Low

EPSS

Percentile

88.0%