Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-4703

Опубликовано: 05 дек. 2014
Источник: debian
EPSS Низкий

Описание

lib/parse_ini.c in Nagios Plugins 2.0.2 allows local users to obtain sensitive information via a symlink attack on the configuration file in the extra-opts flag. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4701.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nagios-pluginsnot-affectedpackage
monitoring-pluginsnot-affectedpackage

Примечания

  • check_dhcp is not installed with root suid permissions in Debian

  • http://seclists.org/fulldisclosure/2014/Jun/141

  • Introduced due to incomplete fix for CVE-2014-4701 in 2.0.2.

EPSS

Процентиль: 63%
0.00443
Низкий

Связанные уязвимости

ubuntu
около 11 лет назад

lib/parse_ini.c in Nagios Plugins 2.0.2 allows local users to obtain sensitive information via a symlink attack on the configuration file in the extra-opts flag. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4701.

redhat
больше 11 лет назад

lib/parse_ini.c in Nagios Plugins 2.0.2 allows local users to obtain sensitive information via a symlink attack on the configuration file in the extra-opts flag. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4701.

nvd
около 11 лет назад

lib/parse_ini.c in Nagios Plugins 2.0.2 allows local users to obtain sensitive information via a symlink attack on the configuration file in the extra-opts flag. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4701.

github
больше 3 лет назад

lib/parse_ini.c in Nagios Plugins 2.0.2 allows local users to obtain sensitive information via a symlink attack on the configuration file in the extra-opts flag. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4701.

EPSS

Процентиль: 63%
0.00443
Низкий