CVE-2014-4703: Low severity nagios plugins vulnerability
Published Dec 5, 2014
·Updated
lib/parseini.c in Nagios Plugins 2.0.2 allows local users to obtain sensitive information via a symlink attack on the configuration file in the extra-opts flag. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4701.
Affected Software
1 affected component
Nagios nagios=2.0.2
Remediation
Patch Available
Event History
Dec 5, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4703?
CVE-2014-4703 is considered a moderate severity vulnerability allowing local users to exploit symlink attacks.
2
How do I fix CVE-2014-4703?
To fix CVE-2014-4703, upgrade to Nagios Plugins version 2.0.3 or later.
3
What does CVE-2014-4703 affect?
CVE-2014-4703 affects Nagios Plugins version 2.0.2, specifically the handling of configuration files.
4
Can CVE-2014-4703 be exploited remotely?
CVE-2014-4703 is a local vulnerability that cannot be exploited remotely.
5
What is a symlink attack in the context of CVE-2014-4703?
A symlink attack involves creating a symbolic link to redirect file access to unauthorized files, potentially exposing sensitive information.