CVE-2013-7108: Input Validation
Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list to the processcgivars function in (1) avail.c, (2) cmd.c, (3) config.c, (4) extinfo.c, (5) histogram.c, (6) notifications.c, (7) outages.c, (8) status.c, (9) statusmap.c, (10) summary.c, and (11) trends.c in cgi/, which triggers a heap-based buffer over-read.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nagios Coreto a version that resolves this vulnerability.Fixed in 3.5.1 - Upgrade
Upgrade
Nagios Coreto a version that resolves this vulnerability.Fixed in 4.0.2 - Upgrade
Upgrade
Icingato a version that resolves this vulnerability.Fixed in 1.8.5 - Upgrade
Upgrade
Icingato a version that resolves this vulnerability.Fixed in 1.9.4 - Upgrade
Upgrade
Icingato a version that resolves this vulnerability.Fixed in 1.10.2
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7108?
CVE-2013-7108 has a severity rating of medium, indicating potential for compromise if exploited.
How do I fix CVE-2013-7108?
To fix CVE-2013-7108, update Nagios to version 4.0.3 or later and Icinga to version 1.10.2 or later.
Which versions of Nagios are affected by CVE-2013-7108?
Affected versions of Nagios include 3.5.1 and 4.0.2 and earlier.
Which versions of Icinga are affected by CVE-2013-7108?
Icinga versions before 1.8.5, specifically 1.9 before 1.9.4 and 1.10 before 1.10.2 are affected.
Can CVE-2013-7108 lead to denial of service attacks?
Yes, CVE-2013-7108 can allow remote authenticated users to cause a denial of service (crash) through specially crafted input.