CVE-2013-7205: Buffer Overflow
Off-by-one error in the processcgivars function in contrib/daemonchk.c in Nagios Core 3.5.1, 4.0.2, and earlier allows remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list, which triggers a heap-based buffer over-read.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7205?
CVE-2013-7205 is considered to have a medium severity rating due to its potential for denial of service and information disclosure.
How do I fix CVE-2013-7205?
To fix CVE-2013-7205, upgrade Nagios to a version later than 4.0.2 or apply the appropriate patches provided by the Nagios development team.
Who is affected by CVE-2013-7205?
CVE-2013-7205 affects Nagios Core versions 3.5.1, 4.0.2, and earlier releases.
What type of vulnerability is CVE-2013-7205?
CVE-2013-7205 is identified as an off-by-one error vulnerability, which can lead to memory corruption.
Can CVE-2013-7205 lead to a denial of service attack?
Yes, CVE-2013-7205 can lead to a denial of service by crashing the Nagios service through a crafted input.