PT-2014-1780 · Icinga · Icinga
Ricardo
·
Published
2014-01-14
·
Updated
2014-02-25
·
CVE-2013-7106
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Icinga versions prior to 1.8.5
Icinga versions prior to 1.9.4
Icinga versions prior to 1.10.2
Description
The issue allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a long string to certain functions, including
display nav table, page limit selector, print export link, page num selector, status page num selector, and display command expansion. It can also be exploited without authentication by leveraging another vulnerability.Recommendations
For Icinga versions prior to 1.8.5, update to version 1.8.5 or later.
For Icinga versions prior to 1.9.4, update to version 1.9.4 or later.
For Icinga versions prior to 1.10.2, update to version 1.10.2 or later.
As a temporary workaround, consider restricting access to the
cgi/cgiutils.c, cgi/status.c, and cgi/config.c files until a patch is available.Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Icinga