CVE-2018-13441: Null Pointer Dereference
Published Jul 12, 2018
·Updated
qhhelp in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.
Affected Software
1 affected component
Nagios nagios<=4.4.1
Event History
Jul 12, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-13441?
CVE-2018-13441 is a vulnerability in Nagios Core version 4.4.1 and earlier that allows an attacker to cause a local denial-of-service condition.
2
How severe is CVE-2018-13441?
CVE-2018-13441 has a severity rating of 5.5 (medium).
3
How does CVE-2018-13441 affect Nagios Core?
CVE-2018-13441 affects Nagios Core version 4.4.1 and earlier.
4
How can an attacker exploit CVE-2018-13441?
An attacker can exploit CVE-2018-13441 by sending a crafted payload to the listening UNIX socket.
5
Is there a fix for CVE-2018-13441?
Yes, upgrading to a version of Nagios Core that is after 4.4.1 will fix CVE-2018-13441.