First published: Fri Dec 05 2014(Updated: )
The check_icmp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configuration files via the extra-opts flag, a different vulnerability than CVE-2014-4701.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Plugins | <=2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4702 is classified as a moderate severity vulnerability.
To fix CVE-2014-4702, upgrade Nagios Plugins to version 2.0.2 or later.
Nagios Plugins versions prior to 2.0.2, specifically versions up to and including 2.0.1, are affected by CVE-2014-4702.
CVE-2014-4702 is a local information disclosure vulnerability related to INI configuration files.
CVE-2014-4702 can be exploited by local users who have access to the affected Nagios system.