Nagios Core 'get_history()' Function Stack Based Buffer Overflow Vulnerability
BID:56879
Info
Nagios Core 'get_history()' Function Stack Based Buffer Overflow Vulnerability
| Bugtraq ID: | 56879 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2012-6096 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2012 12:00AM |
| Updated: | Apr 13 2015 09:33PM |
| Credit: | temp66 |
| Vulnerable: |
Nagios Nagios Core 3.4.3 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Icinga Icinga 1.8.3 Icinga Icinga 1.7.3 Icinga Icinga 1.6.1 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
Icinga Icinga 1.8.4 Icinga Icinga 1.7.4 Icinga Icinga 1.6.2 |
Discussion
Nagios Core 'get_history()' Function Stack Based Buffer Overflow Vulnerability
Nagios Core is prone to a stack-based buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker could exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Nagios Core 3.4.3 is vulnerable; other versions may also be affected.
Nagios Core is prone to a stack-based buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker could exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Nagios Core 3.4.3 is vulnerable; other versions may also be affected.
Exploit / POC
Nagios Core 'get_history()' Function Stack Based Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following example URI and exploit codes are available:
http://www.example.com/nagios/cgi-bin/history.cgi?host=aaaaaaa... (4000 'a's)
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following example URI and exploit codes are available:
http://www.example.com/nagios/cgi-bin/history.cgi?host=aaaaaaa... (4000 'a's)