CVE-2013-1362
high · 7.5Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.
7.5
CVSS
65.7%
EPSS (exploit prob.)
99th
EPSS percentile
2013-07-09
Published
AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| opensuse | opensuse | 11.4 |
| opensuse | opensuse | 12.1 |
| opensuse | opensuse | 12.2 |
| nagios | remote_plug_in_executor | <= 2.13 |
| nagios | remote_plug_in_executor | 1.3 |
| nagios | remote_plug_in_executor | 1.4 |
| nagios | remote_plug_in_executor | 1.5 |
| nagios | remote_plug_in_executor | 1.6 |
| nagios | remote_plug_in_executor | 1.7 |
| nagios | remote_plug_in_executor | 1.8 |
| nagios | remote_plug_in_executor | 1.9 |
| nagios | remote_plug_in_executor | 2.0 |
| nagios | remote_plug_in_executor | 2.0b1 |
| nagios | remote_plug_in_executor | 2.0b2 |
| nagios | remote_plug_in_executor | 2.0b3 |
| nagios | remote_plug_in_executor | 2.0b4 |
| nagios | remote_plug_in_executor | 2.0b5 |
| nagios | remote_plug_in_executor | 2.3 |
| nagios | remote_plug_in_executor | 2.4 |
| nagios | remote_plug_in_executor | 2.5 |
| nagios | remote_plug_in_executor | 2.5.1 |
| nagios | remote_plug_in_executor | 2.5.2 |
| nagios | remote_plug_in_executor | 2.6 |
| nagios | remote_plug_in_executor | 2.7 |
| nagios | remote_plug_in_executor | 2.7.1 |
| nagios | remote_plug_in_executor | 2.8 |
| nagios | remote_plug_in_executor | 2.8.1 |
| nagios | remote_plug_in_executor | 2.8b1 |
| nagios | remote_plug_in_executor | 2.9 |
| nagios | remote_plug_in_executor | 2.10 |
| nagios | remote_plug_in_executor | 2.11 |
| nagios | remote_plug_in_executor | 2.12 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00006.html
- http://seclists.org/bugtraq/2013/Feb/119
- http://www.exploit-db.com/exploits/24955
- http://www.occamsec.com/vulnerabilities.html#nagios_metacharacter_vulnerability
- https://bugzilla.novell.com/show_bug.cgi?id=807241
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00006.html
- http://seclists.org/bugtraq/2013/Feb/119
- http://www.exploit-db.com/exploits/24955
- http://www.occamsec.com/vulnerabilities.html#nagios_metacharacter_vulnerability
- https://bugzilla.novell.com/show_bug.cgi?id=807241
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-1362