Nagios Remote Plugin Executor 'nrpe.c' Remote Code Execution Vulnerability
BID:66969
Info
Nagios Remote Plugin Executor 'nrpe.c' Remote Code Execution Vulnerability
| Bugtraq ID: | 66969 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2913 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 17 2014 12:00AM |
| Updated: | Oct 26 2016 12:01AM |
| Credit: | Dawid Golunski |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 11 SP3 for VMware SuSE SUSE Linux Enterprise Server 11 SP3 Nagios Remote Plug In Executor 2.15 IBM PowerKVM 3.1 IBM PowerKVM 2.1 Gentoo Linux |
| Not Vulnerable: | |
Discussion
Nagios Remote Plugin Executor 'nrpe.c' Remote Code Execution Vulnerability
Nagios Remote Plugin Executor is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context to the affected application.
Nagios Remote Plugin Executor 2.15 and earlier are vulnerable.
Nagios Remote Plugin Executor is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context to the affected application.
Nagios Remote Plugin Executor 2.15 and earlier are vulnerable.
Exploit / POC
Nagios Remote Plugin Executor 'nrpe.c' Remote Code Execution Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Nagios Remote Plugin Executor 'nrpe.c' Remote Code Execution Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Nagios Remote Plugin Executor 'nrpe.c' Remote Code Execution Vulnerability
References:
References: