Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list to the process_cgivars function in (1) avail.c, (2) cmd.c, (3) config.c, (4) extinfo.c, (5) histogram.c, (6) notifications.c, (7) outages.c, (8) status.c, (9) statusmap.c, (10) summary.c, and (11) trends.c in cgi/, which triggers a heap-based buffer over-read.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2014-01-14T18:00:00

Updated: 2018-12-25T10:57:01

Reserved: 2013-12-15T00:00:00


Link: CVE-2013-7108

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2014-01-15T16:08:04.017

Modified: 2018-12-25T11:29:00.353


Link: CVE-2013-7108

JSON object: View

cve-icon Redhat Information

No data.

CWE