CVE-2014-2386: Buffer Overflow
Multiple off-by-one errors in Icinga, possibly 1.10.2 and earlier, allow remote attackers to cause a denial of service (crash) via unspecified vectors to the (1) displaynavtable, (2) printexportlink, (3) pagenumselector, or (4) pagelimitselector function in cgi/cgiutils.c or (5) statuspagenumselector function in cgi/status.c, which triggers a stack-based buffer overflow.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2386?
CVE-2014-2386 has a severity rating that can lead to denial of service due to multiple off-by-one errors.
How do I fix CVE-2014-2386?
To fix CVE-2014-2386, upgrade Icinga to version 1.10.3 or later.
What software is affected by CVE-2014-2386?
CVE-2014-2386 affects Icinga versions up to 1.10.2 and also impacts specific versions of openSUSE.
What types of attacks are possible with CVE-2014-2386?
CVE-2014-2386 allows remote attackers to cause a denial of service attack via specific function vulnerabilities.
Where can I find more information about CVE-2014-2386?
For more information about CVE-2014-2386, you can refer to security advisories and documentation related to Icinga.