First published: Tue Feb 27 2018(Updated: )
An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted (authenticated and unauthenticated) requests, an attacker can exhaust a lot of memory on the server side, triggering the OOM killer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Icinga Icinga | >=2.0.0<=2.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6532 is an issue discovered in Icinga 2.x through 2.8.1 that allows an attacker to exhaust server-side memory.
CVE-2018-6532 affects Icinga 2.x through 2.8.1 by allowing an attacker to exhaust server-side memory.
The severity of CVE-2018-6532 is high (7.5 on the CVSS scale).
An attacker can exploit CVE-2018-6532 by sending specially crafted requests to exhaust server-side memory.
Yes, a fix for CVE-2018-6532 is available. It is recommended to update to Icinga 2.8.2 or later.