CVE-2014-5008: Command Injection
Snoopy allows remote attackers to execute arbitrary commands.
Other sources
Various command-execution flaws were found in the Snoopy library included with Nagios. These flaws allowed remote attackers to execute arbitrary commands by manipulating Nagios HTTP headers.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2014-5008?
CVE-2014-5008 has a high severity rating due to its potential for remote command execution by attackers.
How do I fix CVE-2014-5008?
To fix CVE-2014-5008, upgrade the affected Nagios package to version 0:3.5.1-10.el6 or 0:3.5.1-10.el7.
Which software is affected by CVE-2014-5008?
CVE-2014-5008 affects the Nagios software versions 0:3.5.1-9.el6 and 0:3.5.1-9.el7, as well as the Snoopy library.
What types of attacks can be executed via CVE-2014-5008?
CVE-2014-5008 allows attackers to execute arbitrary commands through the manipulation of Nagios HTTP headers.
Is there a known exploit for CVE-2014-5008?
Yes, CVE-2014-5008 is known to be exploitable, allowing remote attackers to execute commands without authorization.