Multiple stack-based buffer overflows in Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long string to the (1) display_nav_table, (2) page_limit_selector, (3) print_export_link, or (4) page_num_selector function in cgi/cgiutils.c; (5) status_page_num_selector function in cgi/status.c; or (6) display_command_expansion function in cgi/config.c. NOTE: this can be exploited without authentication by leveraging CVE-2013-7107.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2014-01-14T18:00:00

Updated: 2014-01-14T17:57:00

Reserved: 2013-12-15T00:00:00


Link: CVE-2013-7106

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2014-01-15T16:08:03.877

Modified: 2014-02-25T12:19:31.940


Link: CVE-2013-7106

JSON object: View

cve-icon Redhat Information

No data.

CWE