First published: Fri Dec 05 2014(Updated: )
The check_dhcp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configuration files via the extra-opts flag, a different vulnerability than CVE-2014-4702.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Plugins | <=2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4701 is considered a moderate severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-2014-4701, update your Nagios Plugins to version 2.0.2 or later.
Local users of Nagios Plugins versions prior to 2.0.2 are affected by CVE-2014-4701.
CVE-2014-4701 exploits a flaw in the check_dhcp plugin that allows local users to access sensitive information from INI configuration files.
The impact of CVE-2014-4701 is unauthorized access to sensitive configuration information that can compromise system integrity.