CVE-2014-4702: Infoleak
Published Dec 5, 2014
·Updated
The checkicmp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configuration files via the extra-opts flag, a different vulnerability than CVE-2014-4701.
Affected Software
1 affected component
Nagios nagios<=2.0.1
Remediation
Event History
Dec 5, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4702?
CVE-2014-4702 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2014-4702?
To fix CVE-2014-4702, upgrade Nagios Plugins to version 2.0.2 or later.
3
Which versions of Nagios are affected by CVE-2014-4702?
Nagios Plugins versions prior to 2.0.2, specifically versions up to and including 2.0.1, are affected by CVE-2014-4702.
4
What type of vulnerability is CVE-2014-4702?
CVE-2014-4702 is a local information disclosure vulnerability related to INI configuration files.
5
Who can exploit CVE-2014-4702?
CVE-2014-4702 can be exploited by local users who have access to the affected Nagios system.