CVE-2014-5009: Command Injection
Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
Other sources
Various command-execution flaws were found in the Snoopy library included with Nagios. These flaws allowed remote attackers to execute arbitrary commands by manipulating Nagios HTTP headers.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2014-5009?
CVE-2014-5009 is considered a high-severity vulnerability, allowing remote attackers to execute arbitrary commands.
How do I fix CVE-2014-5009?
You can fix CVE-2014-5009 by updating the affected Nagios package to a version higher than 0:3.5.1-9.el6 or 0:3.5.1-9.el7.
Which software is affected by CVE-2014-5009?
CVE-2014-5009 affects various versions of Nagios and the Snoopy library included with it.
Can CVE-2014-5009 impact Nagios installations?
Yes, CVE-2014-5009 can significantly impact Nagios installations, especially those using vulnerable versions.
Does CVE-2014-5009 have a known exploit?
Yes, CVE-2014-5009 has known exploits that allow attackers to execute arbitrary commands remotely.