CVE-2014-1878
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
28/02/2014
Last modified:
12/04/2025
Description
Stack-based buffer overflow in the cmd_submitf function in cgi/cmd.c in Nagios Core, possibly 4.0.3rc1 and earlier, and Icinga before 1.8.6, 1.9 before 1.9.5, and 1.10 before 1.10.3 allows remote attackers to cause a denial of service (segmentation fault) via a long message to cmd.cgi.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:icinga:icinga:*:*:*:*:*:*:*:* | 1.8.5 (including) | |
| cpe:2.3:a:icinga:icinga:1.8.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:icinga:icinga:1.8.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:icinga:icinga:1.8.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:icinga:icinga:1.8.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:icinga:icinga:1.8.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:icinga:icinga:1.9.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:icinga:icinga:1.9.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:icinga:icinga:1.9.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:icinga:icinga:1.9.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:icinga:icinga:1.9.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:icinga:icinga:1.10.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:icinga:icinga:1.10.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:icinga:icinga:1.10.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:nagios:nagios:*:rc1:*:*:*:*:*:* | 4.0.3 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.opensuse.org/opensuse-updates/2014-04/msg00033.html
- http://secunia.com/advisories/57024
- http://www.securityfocus.com/bid/65605
- https://bugzilla.redhat.com/show_bug.cgi?id=1066578
- https://dev.icinga.org/issues/5434
- https://lists.debian.org/debian-lts-announce/2018/12/msg00014.html
- https://www.icinga.org/2014/02/11/bugfix-releases-1-10-3-1-9-5-1-8-6
- http://lists.opensuse.org/opensuse-updates/2014-04/msg00033.html
- http://secunia.com/advisories/57024
- http://www.securityfocus.com/bid/65605
- https://bugzilla.redhat.com/show_bug.cgi?id=1066578
- https://dev.icinga.org/issues/5434
- https://lists.debian.org/debian-lts-announce/2018/12/msg00014.html
- https://www.icinga.org/2014/02/11/bugfix-releases-1-10-3-1-9-5-1-8-6



