CVE-2014-4701: Infoleak
Published Dec 5, 2014
·Updated
The checkdhcp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configuration files via the extra-opts flag, a different vulnerability than CVE-2014-4702.
Affected Software
1 affected component
Nagios nagios<=2.0.1
Remediation
Event History
Dec 5, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4701?
CVE-2014-4701 is considered a moderate severity vulnerability due to the potential exposure of sensitive information.
2
How do I fix CVE-2014-4701?
To fix CVE-2014-4701, update your Nagios Plugins to version 2.0.2 or later.
3
Who is affected by CVE-2014-4701?
Local users of Nagios Plugins versions prior to 2.0.2 are affected by CVE-2014-4701.
4
What does CVE-2014-4701 exploit?
CVE-2014-4701 exploits a flaw in the check_dhcp plugin that allows local users to access sensitive information from INI configuration files.
5
What is the impact of CVE-2014-4701?
The impact of CVE-2014-4701 is unauthorized access to sensitive configuration information that can compromise system integrity.