Off-by-one error in the process_cgivars function in contrib/daemonchk.c in Nagios Core 3.5.1, 4.0.2, and earlier allows remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list, which triggers a heap-based buffer over-read.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2014-01-14T18:00:00
Updated: 2024-08-06T18:01:20.131Z
Reserved: 2013-12-23T00:00:00
Link: CVE-2013-7205
Vulnrichment
No data.
NVD
Status : Modified
Published: 2014-01-15T16:08:04.063
Modified: 2024-11-21T02:00:29.730
Link: CVE-2013-7205
Redhat