Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list to the process_cgivars function in (1) avail.c, (2) cmd.c, (3) config.c, (4) extinfo.c, (5) histogram.c, (6) notifications.c, (7) outages.c, (8) status.c, (9) statusmap.c, (10) summary.c, and (11) trends.c in cgi/, which triggers a heap-based buffer over-read.
2014-01-15T16:08:04.017
2025-04-11T00:51:21.963
Deferred
CVSSv2: 5.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:P
8.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nagios | nagios | ≤ 4.0.2 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0.1 | Yes |
Application | nagios | nagios | 3.0.2 | Yes |
Application | nagios | nagios | 3.0.3 | Yes |
Application | nagios | nagios | 3.0.4 | Yes |
Application | nagios | nagios | 3.0.5 | Yes |
Application | nagios | nagios | 3.0.6 | Yes |
Application | nagios | nagios | 3.1.0 | Yes |
Application | nagios | nagios | 3.1.1 | Yes |
Application | nagios | nagios | 3.1.2 | Yes |
Application | nagios | nagios | 3.2.0 | Yes |
Application | nagios | nagios | 3.2.1 | Yes |
Application | nagios | nagios | 3.2.2 | Yes |
Application | nagios | nagios | 3.2.3 | Yes |
Application | nagios | nagios | 3.3.1 | Yes |
Application | nagios | nagios | 3.4.0 | Yes |
Application | nagios | nagios | 3.4.1 | Yes |
Application | nagios | nagios | 3.4.2 | Yes |
Application | nagios | nagios | 3.4.3 | Yes |
Application | nagios | nagios | 3.5.1 | Yes |
Application | icinga | icinga | ≤ 1.8.4 | Yes |
Application | icinga | icinga | 0.8.0 | Yes |
Application | icinga | icinga | 0.8.1 | Yes |
Application | icinga | icinga | 0.8.2 | Yes |
Application | icinga | icinga | 0.8.3 | Yes |
Application | icinga | icinga | 0.8.4 | Yes |
Application | icinga | icinga | 1.0 | Yes |
Application | icinga | icinga | 1.0 | Yes |
Application | icinga | icinga | 1.0.1 | Yes |
Application | icinga | icinga | 1.0.2 | Yes |
Application | icinga | icinga | 1.0.3 | Yes |
Application | icinga | icinga | 1.2.0 | Yes |
Application | icinga | icinga | 1.2.1 | Yes |
Application | icinga | icinga | 1.3.0 | Yes |
Application | icinga | icinga | 1.3.1 | Yes |
Application | icinga | icinga | 1.4.0 | Yes |
Application | icinga | icinga | 1.4.1 | Yes |
Application | icinga | icinga | 1.6.0 | Yes |
Application | icinga | icinga | 1.6.1 | Yes |
Application | icinga | icinga | 1.6.2 | Yes |
Application | icinga | icinga | 1.7.0 | Yes |
Application | icinga | icinga | 1.7.1 | Yes |
Application | icinga | icinga | 1.7.2 | Yes |
Application | icinga | icinga | 1.7.3 | Yes |
Application | icinga | icinga | 1.7.4 | Yes |
Application | icinga | icinga | 1.8.0 | Yes |
Application | icinga | icinga | 1.8.1 | Yes |
Application | icinga | icinga | 1.8.2 | Yes |
Application | icinga | icinga | 1.8.3 | Yes |
Application | icinga | icinga | 1.9.0 | Yes |
Application | icinga | icinga | 1.9.1 | Yes |
Application | icinga | icinga | 1.9.2 | Yes |
Application | icinga | icinga | 1.9.3 | Yes |
Application | icinga | icinga | 1.10.0 | Yes |
Application | icinga | icinga | 1.10.1 | Yes |