CVE-2018-6532: High severity Icinga Icinga vulnerability
Published Feb 27, 2018
·Updated
An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted (authenticated and unauthenticated) requests, an attacker can exhaust a lot of memory on the server side, triggering the OOM killer.
Affected Software
1 affected component
Icinga Icinga>=2.0.0<=2.8.0
Event History
Feb 27, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2018-6532?
CVE-2018-6532 is an issue discovered in Icinga 2.x through 2.8.1 that allows an attacker to exhaust server-side memory.
2
How does CVE-2018-6532 affect Icinga?
CVE-2018-6532 affects Icinga 2.x through 2.8.1 by allowing an attacker to exhaust server-side memory.
3
What is the severity of CVE-2018-6532?
The severity of CVE-2018-6532 is high (7.5 on the CVSS scale).
4
How can an attacker exploit CVE-2018-6532?
An attacker can exploit CVE-2018-6532 by sending specially crafted requests to exhaust server-side memory.
5
Is there a fix available for CVE-2018-6532?
Yes, a fix for CVE-2018-6532 is available. It is recommended to update to Icinga 2.8.2 or later.