MGASA-2014-0010

Source
https://advisories.mageia.org/MGASA-2014-0010.html
Import Source
https://advisories.mageia.org/MGASA-2014-0010.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0010
Related
  • CVE-2013-7108
  • CVE-2013-7205
Published
2014-01-17T00:22:05Z
Modified
2014-01-17T00:22:01Z
Summary
Updated nagios package fixes security vulnerability
Details

A flaw was reported and fixed in Nagios, which can be exploited to cause a denial of service. This vulnerability is caused due to an off-by-one error within the process_cgivars() function, which can be exploited to cause an out-of-bounds read by sending a specially-crafted key value to the Nagios web UI (CVE-2013-7108, CVE-2013-7205). An issue that prevented the service from starting has also been fixed.

References
Credits

Affected packages

Mageia:3 / nagios

Package

Name
nagios
Purl
pkg:rpm/mageia/nagios?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.4.4-4.2.mga3

Ecosystem specific

{
    "section": "core"
}