Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-7205

Опубликовано: 15 янв. 2014
Источник: ubuntu
Приоритет: low
CVSS2: 6.4

Описание

Off-by-one error in the process_cgivars function in contrib/daemonchk.c in Nagios Core 3.5.1, 4.0.2, and earlier allows remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list, which triggers a heap-based buffer over-read.

РелизСтатусПримечание
devel

released

3.5.1.dfsg-2.1ubuntu5
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [3.5.1-1ubuntu1.1]]
esm-infra/xenial

released

3.5.1.dfsg-2.1ubuntu1.1
lucid

ignored

end of life
precise

ignored

end of life
precise/esm

DNE

precise was needed
quantal

ignored

end of life
raring

ignored

end of life
saucy

ignored

end of life
trusty

released

3.5.1-1ubuntu1.1

Показывать по

6.4 Medium

CVSS2

Связанные уязвимости

redhat
около 12 лет назад

Off-by-one error in the process_cgivars function in contrib/daemonchk.c in Nagios Core 3.5.1, 4.0.2, and earlier allows remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list, which triggers a heap-based buffer over-read.

nvd
около 12 лет назад

Off-by-one error in the process_cgivars function in contrib/daemonchk.c in Nagios Core 3.5.1, 4.0.2, and earlier allows remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list, which triggers a heap-based buffer over-read.

debian
около 12 лет назад

Off-by-one error in the process_cgivars function in contrib/daemonchk. ...

github
больше 3 лет назад

Off-by-one error in the process_cgivars function in contrib/daemonchk.c in Nagios Core 3.5.1, 4.0.2, and earlier allows remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list, which triggers a heap-based buffer over-read.

6.4 Medium

CVSS2