Lucene search

K
cve[email protected]CVE-2014-1878
HistoryFeb 28, 2014 - 3:13 p.m.

CVE-2014-1878

2014-02-2815:13:04
CWE-119
web.nvd.nist.gov
48
cve-2014-1878
buffer overflow
nagios core
icinga
denial of service
remote attackers

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

AI Score

Confidence

High

0.046 Low

EPSS

Percentile

92.6%

Stack-based buffer overflow in the cmd_submitf function in cgi/cmd.c in Nagios Core, possibly 4.0.3rc1 and earlier, and Icinga before 1.8.6, 1.9 before 1.9.5, and 1.10 before 1.10.3 allows remote attackers to cause a denial of service (segmentation fault) via a long message to cmd.cgi.

Affected configurations

NVD
Node
icingaicingaRange1.8.5
OR
icingaicingaMatch1.8.0
OR
icingaicingaMatch1.8.1
OR
icingaicingaMatch1.8.2
OR
icingaicingaMatch1.8.3
OR
icingaicingaMatch1.8.4
OR
icingaicingaMatch1.9.0
OR
icingaicingaMatch1.9.1
OR
icingaicingaMatch1.9.2
OR
icingaicingaMatch1.9.3
OR
icingaicingaMatch1.9.4
OR
icingaicingaMatch1.10.0
OR
icingaicingaMatch1.10.1
OR
icingaicingaMatch1.10.2
OR
nagiosnagiosRange4.0.3rc1
OR
nagiosnagiosMatch4.0.0beta1
OR
nagiosnagiosMatch4.0.0beta2
OR
nagiosnagiosMatch4.0.0beta3
OR
nagiosnagiosMatch4.0.0beta4
OR
nagiosnagiosMatch4.0.2

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

AI Score

Confidence

High

0.046 Low

EPSS

Percentile

92.6%