Stack-based buffer overflow in the cmd_submitf function in cgi/cmd.c in Nagios Core, possibly 4.0.3rc1 and earlier, and Icinga before 1.8.6, 1.9 before 1.9.5, and 1.10 before 1.10.3 allows remote attackers to cause a denial of service (segmentation fault) via a long message to cmd.cgi.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "3.5.1-1ubuntu1.1", "binary_name": "nagios3" }, { "binary_version": "3.5.1-1ubuntu1.1", "binary_name": "nagios3-cgi" }, { "binary_version": "3.5.1-1ubuntu1.1", "binary_name": "nagios3-cgi-dbgsym" }, { "binary_version": "3.5.1-1ubuntu1.1", "binary_name": "nagios3-common" }, { "binary_version": "3.5.1-1ubuntu1.1", "binary_name": "nagios3-core" }, { "binary_version": "3.5.1-1ubuntu1.1", "binary_name": "nagios3-core-dbgsym" }, { "binary_version": "3.5.1-1ubuntu1.1", "binary_name": "nagios3-dbg" }, { "binary_version": "3.5.1-1ubuntu1.1", "binary_name": "nagios3-dbgsym" }, { "binary_version": "3.5.1-1ubuntu1.1", "binary_name": "nagios3-doc" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "3.5.1.dfsg-2.1ubuntu1.1", "binary_name": "nagios3" }, { "binary_version": "3.5.1.dfsg-2.1ubuntu1.1", "binary_name": "nagios3-cgi" }, { "binary_version": "3.5.1.dfsg-2.1ubuntu1.1", "binary_name": "nagios3-cgi-dbgsym" }, { "binary_version": "3.5.1.dfsg-2.1ubuntu1.1", "binary_name": "nagios3-common" }, { "binary_version": "3.5.1.dfsg-2.1ubuntu1.1", "binary_name": "nagios3-core" }, { "binary_version": "3.5.1.dfsg-2.1ubuntu1.1", "binary_name": "nagios3-core-dbgsym" }, { "binary_version": "3.5.1.dfsg-2.1ubuntu1.1", "binary_name": "nagios3-dbg" }, { "binary_version": "3.5.1.dfsg-2.1ubuntu1.1", "binary_name": "nagios3-dbgsym" }, { "binary_version": "3.5.1.dfsg-2.1ubuntu1.1", "binary_name": "nagios3-doc" } ] }