CVE-2013-7108
Summary
| CVE | CVE-2013-7108 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-01-15 16:08:04 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list to the process_cgivars function in (1) avail.c, (2) cmd.c, (3) config.c, (4) extinfo.c, (5) histogram.c, (6) notifications.c, (7) outages.c, (8) status.c, (9) statusmap.c, (10) summary.c, and (11) trends.c in cgi/, which triggers a heap-based buffer over-read. |
Risk And Classification
Primary CVSS: v2.0 5.5 from [email protected]
AV:N/AC:L/Au:S/C:P/I:N/A:P
EPSS: 0.485770000 probability, percentile 0.977680000 (date 2026-05-01)
Problem Types: CWE-20 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:S/C:P/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Icinga | Icinga | 0.8.0 | All | All | All |
| Application | Icinga | Icinga | 0.8.1 | All | All | All |
| Application | Icinga | Icinga | 0.8.2 | All | All | All |
| Application | Icinga | Icinga | 0.8.3 | All | All | All |
| Application | Icinga | Icinga | 0.8.4 | All | All | All |
| Application | Icinga | Icinga | 1.0 | All | All | All |
| Application | Icinga | Icinga | 1.0 | rc1 | All | All |
| Application | Icinga | Icinga | 1.0.1 | All | All | All |
| Application | Icinga | Icinga | 1.0.2 | All | All | All |
| Application | Icinga | Icinga | 1.0.3 | All | All | All |
| Application | Icinga | Icinga | 1.10.0 | All | All | All |
| Application | Icinga | Icinga | 1.10.1 | All | All | All |
| Application | Icinga | Icinga | 1.2.0 | All | All | All |
| Application | Icinga | Icinga | 1.2.1 | All | All | All |
| Application | Icinga | Icinga | 1.3.0 | All | All | All |
| Application | Icinga | Icinga | 1.3.1 | All | All | All |
| Application | Icinga | Icinga | 1.4.0 | All | All | All |
| Application | Icinga | Icinga | 1.4.1 | All | All | All |
| Application | Icinga | Icinga | 1.6.0 | All | All | All |
| Application | Icinga | Icinga | 1.6.1 | All | All | All |
| Application | Icinga | Icinga | 1.6.2 | All | All | All |
| Application | Icinga | Icinga | 1.7.0 | All | All | All |
| Application | Icinga | Icinga | 1.7.1 | All | All | All |
| Application | Icinga | Icinga | 1.7.2 | All | All | All |
| Application | Icinga | Icinga | 1.7.3 | All | All | All |
| Application | Icinga | Icinga | 1.7.4 | All | All | All |
| Application | Icinga | Icinga | 1.8.0 | All | All | All |
| Application | Icinga | Icinga | 1.8.1 | All | All | All |
| Application | Icinga | Icinga | 1.8.2 | All | All | All |
| Application | Icinga | Icinga | 1.8.3 | All | All | All |
| Application | Icinga | Icinga | 1.9.0 | All | All | All |
| Application | Icinga | Icinga | 1.9.1 | All | All | All |
| Application | Icinga | Icinga | 1.9.2 | All | All | All |
| Application | Icinga | Icinga | 1.9.3 | All | All | All |
| Application | Icinga | Icinga | All | All | All | All |
| Application | Nagios | Nagios | 3.0 | All | All | All |
| Application | Nagios | Nagios | 3.0 | alpha1 | All | All |
| Application | Nagios | Nagios | 3.0 | alpha2 | All | All |
| Application | Nagios | Nagios | 3.0 | alpha3 | All | All |
| Application | Nagios | Nagios | 3.0 | alpha4 | All | All |
| Application | Nagios | Nagios | 3.0 | alpha5 | All | All |
| Application | Nagios | Nagios | 3.0 | beta1 | All | All |
| Application | Nagios | Nagios | 3.0 | beta2 | All | All |
| Application | Nagios | Nagios | 3.0 | beta3 | All | All |
| Application | Nagios | Nagios | 3.0 | beta4 | All | All |
| Application | Nagios | Nagios | 3.0 | beta5 | All | All |
| Application | Nagios | Nagios | 3.0 | beta6 | All | All |
| Application | Nagios | Nagios | 3.0 | beta7 | All | All |
| Application | Nagios | Nagios | 3.0 | rc1 | All | All |
| Application | Nagios | Nagios | 3.0 | rc2 | All | All |
| Application | Nagios | Nagios | 3.0 | rc3 | All | All |
| Application | Nagios | Nagios | 3.0.1 | All | All | All |
| Application | Nagios | Nagios | 3.0.2 | All | All | All |
| Application | Nagios | Nagios | 3.0.3 | All | All | All |
| Application | Nagios | Nagios | 3.0.4 | All | All | All |
| Application | Nagios | Nagios | 3.0.5 | All | All | All |
| Application | Nagios | Nagios | 3.0.6 | All | All | All |
| Application | Nagios | Nagios | 3.1.0 | All | All | All |
| Application | Nagios | Nagios | 3.1.1 | All | All | All |
| Application | Nagios | Nagios | 3.1.2 | All | All | All |
| Application | Nagios | Nagios | 3.2.0 | All | All | All |
| Application | Nagios | Nagios | 3.2.1 | All | All | All |
| Application | Nagios | Nagios | 3.2.2 | All | All | All |
| Application | Nagios | Nagios | 3.2.3 | All | All | All |
| Application | Nagios | Nagios | 3.3.1 | All | All | All |
| Application | Nagios | Nagios | 3.4.0 | All | All | All |
| Application | Nagios | Nagios | 3.4.1 | All | All | All |
| Application | Nagios | Nagios | 3.4.2 | All | All | All |
| Application | Nagios | Nagios | 3.4.3 | All | All | All |
| Application | Nagios | Nagios | 3.5.1 | All | All | All |
| Application | Nagios | Nagios | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Re: CVE request: denial of service in Nagios (process_cgivars()) | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Icinga Web GUI CVE-2013-7108 Multiple Off-By-One Memory Corruption Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| openSUSE-SU-2014:0039-1: moderate: nagios: fixed a denial of service in | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Security Advisory SA55976 - Nagios "process_cgivars()" Off-By-One Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Icinga Security Releases – 1.10.2, 1.9.4, 1.8.5 - - Icinga: Open Source Monitoring | af854a3a-2127-422b-91ae-364da2661108 | www.icinga.org | |
| Nagios Core / Nagios Core / Commit [d97e03] | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| Support / Security / Advisories / / MDVSA-2014:004 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| openSUSE-SU-2014:0097-1: moderate: update for icinga | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Security Advisory SA56316 - SUSE update for nagios - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [SECURITY] [DLA 1615-1] nagios3 security update | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | |
| Bug #5251: fix Off-by-one memory access in process_cgivars() CVE-2013-7108 - Classic UI - Open Source Monitoring | af854a3a-2127-422b-91ae-364da2661108 | dev.icinga.org | Vendor Advisory |
| openSUSE-SU-2014:0016-1: moderate: nagios: fixed a denial of service in | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| openSUSE-SU-2014:0069-1: moderate: update for icinga | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.