Icinga 'cgi/cmd.c' Stack Buffer Overflow Vulnerability
BID:65605
Info
Icinga 'cgi/cmd.c' Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 65605 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-1878 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2014 12:00AM |
| Updated: | Oct 26 2016 05:00AM |
| Credit: | GitHub security team and Dirkjan Bussink |
| Vulnerable: |
S.u.S.E. openSUSE 13.1 S.u.S.E. openSUSE 12.3 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Icinga Icinga 1.9.4 Icinga Icinga 1.8.5 Icinga Icinga 1.10.2 IBM PowerKVM 3.1 IBM PowerKVM 2.1 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
Icinga Icinga 1.10.3 Icinga Icinga 1.9.5 Icinga Icinga 1.8.6 |
Discussion
Icinga 'cgi/cmd.c' Stack Buffer Overflow Vulnerability
Icinga is prone to a stack-based buffer-overflow vulnerability because it fails to adequately bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in denial-of-service conditions.
Icinga prior to 1.10.3, 1.9.5 and 1.8.6 are vulnerable.
Icinga is prone to a stack-based buffer-overflow vulnerability because it fails to adequately bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in denial-of-service conditions.
Icinga prior to 1.10.3, 1.9.5 and 1.8.6 are vulnerable.
Exploit / POC
Icinga 'cgi/cmd.c' Stack Buffer Overflow Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Icinga 'cgi/cmd.c' Stack Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva nagios-3.1.2-0.6mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva nagios-devel-3.1.2-0.6mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva nagios-theme-default-3.1.2-0.6mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva nagios-www-3.1.2-0.6mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva nagios-3.1.2-0.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva nagios-devel-3.1.2-0.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva nagios-theme-default-3.1.2-0.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva nagios-www-3.1.2-0.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Business Server 1 X86 64
-
Mandriva nagios-3.4.4-4.2.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva nagios-devel-3.4.4-4.2.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva nagios-www-3.4.4-4.2.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
Icinga 'cgi/cmd.c' Stack Buffer Overflow Vulnerability
References:
References: