Lucene search

K
debianDebianDEBIAN:DLA-60-1:5B1EB
HistorySep 24, 2014 - 4:14 p.m.

[SECURITY] [DLA 60-1] icinga security update

2014-09-2416:14:21
lists.debian.org
11

5.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:N/A:P

7.8 High

AI Score

Confidence

High

0.941 High

EPSS

Percentile

99.2%

Package : icinga
Version : 1.0.2-2+squeeze2
CVE ID : CVE-2013-7108 CVE-2014-1878

Two fixes for the Classic UI:

  • fix off-by-one memory access in process_cgivars() (CVE-2013-7108)
  • prevent possible buffer overflows in cmd.cgi (CVE-2014-1878)
    Attachment:
    signature.asc
    Description: This is a digitally signed message part.

5.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:N/A:P

7.8 High

AI Score

Confidence

High

0.941 High

EPSS

Percentile

99.2%