Nagios Remote Content-Length Integer Overflow Vulnerability
BID:18059
CVE-2006-2489 |Info
Nagios Remote Content-Length Integer Overflow Vulnerability
| Bugtraq ID: | 18059 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-2489 |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2006 12:00AM |
| Updated: | Nov 15 2007 12:35AM |
| Credit: | Sean Finney and Debian are credited with the discovery of this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Nagios Nagios 1.0 b4 Nagios Nagios 1.0 b3 Nagios Nagios 1.0 b2 Nagios Nagios 1.0 b1 Nagios Nagios 2.3 Nagios Nagios 2.2 Nagios Nagios 1.4 Nagios Nagios 1.3 Nagios Nagios 0 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
Nagios Nagios 2.3.1 Nagios Nagios 1.4.1 |
Discussion
Nagios Remote Content-Length Integer Overflow Vulnerability
Nagios is prone to a remote integer-overflow vulnerability. The application fails to properly ensure that user-supplied input doesn't overflow integer values. This may result in user-supplied data being copied past the end of a memory buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of hosting webservers.
Nagios versions prior to 2.3.1 are vulnerable to this issue.
This issue is very similar to BID 17879 (Nagios Remote Negative Content-Length Buffer Overflow Vulnerability), but is a separate issue.
Nagios is prone to a remote integer-overflow vulnerability. The application fails to properly ensure that user-supplied input doesn't overflow integer values. This may result in user-supplied data being copied past the end of a memory buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of hosting webservers.
Nagios versions prior to 2.3.1 are vulnerable to this issue.
This issue is very similar to BID 17879 (Nagios Remote Negative Content-Length Buffer Overflow Vulnerability), but is a separate issue.
Exploit / POC
Nagios Remote Content-Length Integer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Nagios Remote Content-Length Integer Overflow Vulnerability
Solution:
The vendor has released version 2.3.1 of Nagios to address this issue.
Please see the referenced advisories for further information on obtaining and applying fixes.
Nagios Nagios 2.2
Nagios Nagios 1.4
Nagios Nagios 1.3
Nagios Nagios 2.3
Solution:
The vendor has released version 2.3.1 of Nagios to address this issue.
Please see the referenced advisories for further information on obtaining and applying fixes.
Nagios Nagios 2.2
-
Nagios nagios-2.3.1.tar.gz
http://prdownloads.sourceforge.net/nagios/nagios-2.3.1.tar.gz?download
Nagios Nagios 1.4
-
Nagios nagios-1.4.1.tar.gz
http://prdownloads.sourceforge.net/nagios/nagios-1.4.1.tar.gz?download
Nagios Nagios 1.3
-
Debian nagios-common_1.3-cvs.20050402-2.sarge.2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-common_1. 3-cvs.20050402-2.sarge.2_all.deb -
Debian nagios-mysql_1.3-cvs.20050402-2.sarge.2_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-mysql_1.3 -cvs.20050402-2.sarge.2_alpha.deb -
Debian nagios-mysql_1.3-cvs.20050402-2.sarge.2_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-mysql_1.3 -cvs.20050402-2.sarge.2_amd64.deb -
Debian nagios-mysql_1.3-cvs.20050402-2.sarge.2_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-mysql_1.3 -cvs.20050402-2.sarge.2_arm.deb -
Debian nagios-mysql_1.3-cvs.20050402-2.sarge.2_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-mysql_1.3 -cvs.20050402-2.sarge.2_hppa.deb -
Debian nagios-mysql_1.3-cvs.20050402-2.sarge.2_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-mysql_1.3 -cvs.20050402-2.sarge.2_i386.deb -
Debian nagios-mysql_1.3-cvs.20050402-2.sarge.2_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-mysql_1.3 -cvs.20050402-2.sarge.2_ia64.deb -
Debian nagios-mysql_1.3-cvs.20050402-2.sarge.2_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-mysql_1.3 -cvs.20050402-2.sarge.2_m68k.deb -
Debian nagios-mysql_1.3-cvs.20050402-2.sarge.2_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-mysql_1.3 -cvs.20050402-2.sarge.2_mips.deb -
Debian nagios-mysql_1.3-cvs.20050402-2.sarge.2_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-mysql_1.3 -cvs.20050402-2.sarge.2_mipsel.deb -
Debian nagios-mysql_1.3-cvs.20050402-2.sarge.2_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-mysql_1.3 -cvs.20050402-2.sarge.2_powerpc.deb -
Debian nagios-mysql_1.3-cvs.20050402-2.sarge.2_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-mysql_1.3 -cvs.20050402-2.sarge.2_s390.deb -
Debian nagios-mysql_1.3-cvs.20050402-2.sarge.2_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-mysql_1.3 -cvs.20050402-2.sarge.2_sparc.deb -
Debian nagios-pgsql_1.3-cvs.20050402-2.sarge.2_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-pgsql_1.3 -cvs.20050402-2.sarge.2_alpha.deb -
Debian nagios-pgsql_1.3-cvs.20050402-2.sarge.2_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-pgsql_1.3 -cvs.20050402-2.sarge.2_amd64.deb -
Debian nagios-pgsql_1.3-cvs.20050402-2.sarge.2_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-pgsql_1.3 -cvs.20050402-2.sarge.2_arm.deb -
Debian nagios-pgsql_1.3-cvs.20050402-2.sarge.2_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-pgsql_1.3 -cvs.20050402-2.sarge.2_hppa.deb -
Debian nagios-pgsql_1.3-cvs.20050402-2.sarge.2_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-pgsql_1.3 -cvs.20050402-2.sarge.2_i386.deb -
Debian nagios-pgsql_1.3-cvs.20050402-2.sarge.2_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-pgsql_1.3 -cvs.20050402-2.sarge.2_ia64.deb -
Debian nagios-pgsql_1.3-cvs.20050402-2.sarge.2_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-pgsql_1.3 -cvs.20050402-2.sarge.2_m68k.deb -
Debian nagios-pgsql_1.3-cvs.20050402-2.sarge.2_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-pgsql_1.3 -cvs.20050402-2.sarge.2_mips.deb -
Debian nagios-pgsql_1.3-cvs.20050402-2.sarge.2_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-pgsql_1.3 -cvs.20050402-2.sarge.2_mipsel.deb -
Debian nagios-pgsql_1.3-cvs.20050402-2.sarge.2_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-pgsql_1.3 -cvs.20050402-2.sarge.2_powerpc.deb -
Debian nagios-pgsql_1.3-cvs.20050402-2.sarge.2_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-pgsql_1.3 -cvs.20050402-2.sarge.2_s390.deb -
Debian nagios-pgsql_1.3-cvs.20050402-2.sarge.2_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-pgsql_1.3 -cvs.20050402-2.sarge.2_sparc.deb -
Debian nagios-text_1.3-cvs.20050402-2.sarge.2_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-text_1.3- cvs.20050402-2.sarge.2_alpha.deb -
Debian nagios-text_1.3-cvs.20050402-2.sarge.2_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-text_1.3- cvs.20050402-2.sarge.2_amd64.deb -
Debian nagios-text_1.3-cvs.20050402-2.sarge.2_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-text_1.3- cvs.20050402-2.sarge.2_arm.deb -
Debian nagios-text_1.3-cvs.20050402-2.sarge.2_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-text_1.3- cvs.20050402-2.sarge.2_hppa.deb -
Debian nagios-text_1.3-cvs.20050402-2.sarge.2_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-text_1.3- cvs.20050402-2.sarge.2_i386.deb -
Debian nagios-text_1.3-cvs.20050402-2.sarge.2_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-text_1.3- cvs.20050402-2.sarge.2_ia64.deb -
Debian nagios-text_1.3-cvs.20050402-2.sarge.2_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-text_1.3- cvs.20050402-2.sarge.2_m68k.deb -
Debian nagios-text_1.3-cvs.20050402-2.sarge.2_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-text_1.3- cvs.20050402-2.sarge.2_mips.deb -
Debian nagios-text_1.3-cvs.20050402-2.sarge.2_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-text_1.3- cvs.20050402-2.sarge.2_mipsel.deb -
Debian nagios-text_1.3-cvs.20050402-2.sarge.2_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-text_1.3- cvs.20050402-2.sarge.2_powerpc.deb -
Debian nagios-text_1.3-cvs.20050402-2.sarge.2_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-text_1.3- cvs.20050402-2.sarge.2_s390.deb -
Debian nagios-text_1.3-cvs.20050402-2.sarge.2_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/n/nagios/nagios-text_1.3- cvs.20050402-2.sarge.2_sparc.deb -
Nagios nagios-1.4.1.tar.gz
http://prdownloads.sourceforge.net/nagios/nagios-1.4.1.tar.gz?download -
Ubuntu nagios-common_1.3-0+pre6ubuntu0.2_all.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/n/nagios/nagios-common_1.3 -0+pre6ubuntu0.2_all.deb -
Ubuntu nagios-common_1.3-cvs.20050402-4ubuntu3.2_all.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/n/nagios/nagios-common_1.3 -cvs.20050402-4ubuntu3.2_all.deb -
Ubuntu nagios-mysql_1.3-0+pre6ubuntu0.2_amd64.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/n/nagios/nagios-mysql_1.3- 0+pre6ubuntu0.2_amd64.deb -
Ubuntu nagios-mysql_1.3-0+pre6ubuntu0.2_i386.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/n/nagios/nagios-mysql_1.3- 0+pre6ubuntu0.2_i386.deb -
Ubuntu nagios-mysql_1.3-0+pre6ubuntu0.2_powerpc.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/n/nagios/nagios-mysql_1.3- 0+pre6ubuntu0.2_powerpc.deb -
Ubuntu nagios-mysql_1.3-cvs.20050402-4ubuntu3.2_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/n/nagios/nagios-mysql_1.3- cvs.20050402-4ubuntu3.2_amd64.deb -
Ubuntu nagios-mysql_1.3-cvs.20050402-4ubuntu3.2_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/n/nagios/nagios-mysql_1.3- cvs.20050402-4ubuntu3.2_i386.deb -
Ubuntu nagios-mysql_1.3-cvs.20050402-4ubuntu3.2_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/n/nagios/nagios-mysql_1.3- cvs.20050402-4ubuntu3.2_powerpc.deb -
Ubuntu nagios-pgsql_1.3-0+pre6ubuntu0.2_amd64.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/n/nagios/nagios-pgsql_1.3- 0+pre6ubuntu0.2_amd64.deb -
Ubuntu nagios-pgsql_1.3-0+pre6ubuntu0.2_i386.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/n/nagios/nagios-pgsql_1.3- 0+pre6ubuntu0.2_i386.deb -
Ubuntu nagios-pgsql_1.3-0+pre6ubuntu0.2_powerpc.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/n/nagios/nagios-pgsql_1.3- 0+pre6ubuntu0.2_powerpc.deb -
Ubuntu nagios-pgsql_1.3-cvs.20050402-4ubuntu3.2_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/n/nagios/nagios-pgsql_1.3- cvs.20050402-4ubuntu3.2_amd64.deb -
Ubuntu nagios-pgsql_1.3-cvs.20050402-4ubuntu3.2_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/n/nagios/nagios-pgsql_1.3- cvs.20050402-4ubuntu3.2_i386.deb -
Ubuntu nagios-pgsql_1.3-cvs.20050402-4ubuntu3.2_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/n/nagios/nagios-pgsql_1.3- cvs.20050402-4ubuntu3.2_powerpc.deb -
Ubuntu nagios-text_1.3-0+pre6ubuntu0.2_amd64.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/n/nagios/nagios-text_1.3-0 +pre6ubuntu0.2_amd64.deb -
Ubuntu nagios-text_1.3-0+pre6ubuntu0.2_i386.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/n/nagios/nagios-text_1.3-0 +pre6ubuntu0.2_i386.deb -
Ubuntu nagios-text_1.3-0+pre6ubuntu0.2_powerpc.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/n/nagios/nagios-text_1.3-0 +pre6ubuntu0.2_powerpc.deb -
Ubuntu nagios-text_1.3-cvs.20050402-4ubuntu3.2_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/n/nagios/nagios-text_1.3-c vs.20050402-4ubuntu3.2_amd64.deb -
Ubuntu nagios-text_1.3-cvs.20050402-4ubuntu3.2_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/n/nagios/nagios-text_1.3-c vs.20050402-4ubuntu3.2_i386.deb -
Ubuntu nagios-text_1.3-cvs.20050402-4ubuntu3.2_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/n/nagios/nagios-text_1.3-c vs.20050402-4ubuntu3.2_powerpc.deb
Nagios Nagios 2.3
-
Nagios nagios-2.3.1.tar.gz
http://prdownloads.sourceforge.net/nagios/nagios-2.3.1.tar.gz?download
References
Nagios Remote Content-Length Integer Overflow Vulnerability
References:
References:
- Nagios ChangeLog (Nagios)
- Nagios Homepage (Nagios)