← All CVEs

CVE-2013-7108

medium · 5.5

Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list to the process_cgivars function in (1) avail.c, (2) cmd.c, (3) config.c, (4) extinfo.c, (5) histogram.c, (6) notifications.c, (7) outages.c, (8) status.c, (9) statusmap.c, (10) summary.c, and (11) trends.c in cgi/, which triggers a heap-based buffer over-read.

5.5
CVSS
59.5%
EPSS (exploit prob.)
99th
EPSS percentile
2014-01-15
Published

AV:N/AC:L/Au:S/C:P/I:N/A:P

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
nagiosnagios<= 4.0.2
nagiosnagios3.0
nagiosnagios3.0
nagiosnagios3.0
nagiosnagios3.0
nagiosnagios3.0
nagiosnagios3.0
nagiosnagios3.0
nagiosnagios3.0
nagiosnagios3.0
nagiosnagios3.0
nagiosnagios3.0
nagiosnagios3.0
nagiosnagios3.0
nagiosnagios3.0
nagiosnagios3.0
nagiosnagios3.0
nagiosnagios3.0.1
nagiosnagios3.0.2
nagiosnagios3.0.3
nagiosnagios3.0.4
nagiosnagios3.0.5
nagiosnagios3.0.6
nagiosnagios3.1.0
nagiosnagios3.1.1
nagiosnagios3.1.2
nagiosnagios3.2.0
nagiosnagios3.2.1
nagiosnagios3.2.2
nagiosnagios3.2.3
nagiosnagios3.3.1
nagiosnagios3.4.0
nagiosnagios3.4.1
nagiosnagios3.4.2
nagiosnagios3.4.3
nagiosnagios3.5.1
icingaicinga<= 1.8.4
icingaicinga0.8.0
icingaicinga0.8.1
icingaicinga0.8.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-7108