Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list to the process_cgivars function in (1) avail.c, (2) cmd.c, (3) config.c, (4) extinfo.c, (5) histogram.c, (6) notifications.c, (7) outages.c, (8) status.c, (9) statusmap.c, (10) summary.c, and (11) trends.c in cgi/, which triggers a heap-based buffer over-read.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2014-01-14T18:00:00

Updated: 2024-08-06T18:01:19.334Z

Reserved: 2013-12-15T00:00:00

Link: CVE-2013-7108

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2014-01-15T16:08:04.017

Modified: 2018-12-25T11:29:00.353

Link: CVE-2013-7108

cve-icon Redhat

Severity : Moderate

Publid Date: 2013-12-20T00:00:00Z

Links: CVE-2013-7108 - Bugzilla