CVE-2013-7106

Multiple stack-based buffer overflows in Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long string to the (1) display_nav_table, (2) page_limit_selector, (3) print_export_link, or (4) page_num_selector function in cgi/cgiutils.c; (5) status_page_num_selector function in cgi/status.c; or (6) display_command_expansion function in cgi/config.c.  NOTE: this can be exploited without authentication by leveraging CVE-2013-7107.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
VendorProductVersion
icingaicinga
𝑥
≤ 1.8.4
icingaicinga
0.8.0
icingaicinga
0.8.1
icingaicinga
0.8.2
icingaicinga
0.8.3
icingaicinga
0.8.4
icingaicinga
1.0
icingaicinga
1.0:rc1
icingaicinga
1.0.1
icingaicinga
1.0.2
icingaicinga
1.0.3
icingaicinga
1.2.0
icingaicinga
1.2.1
icingaicinga
1.3.0
icingaicinga
1.3.1
icingaicinga
1.4.0
icingaicinga
1.4.1
icingaicinga
1.6.0
icingaicinga
1.6.1
icingaicinga
1.6.2
icingaicinga
1.7.0
icingaicinga
1.7.1
icingaicinga
1.7.2
icingaicinga
1.7.3
icingaicinga
1.7.4
icingaicinga
1.8.0
icingaicinga
1.8.1
icingaicinga
1.8.2
icingaicinga
1.8.3
icingaicinga
1.9.0
icingaicinga
1.9.1
icingaicinga
1.9.2
icingaicinga
1.9.3
icingaicinga
1.10.0
icingaicinga
1.10.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
icinga
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
dne
saucy
ignored
raring
ignored
quantal
ignored
precise
ignored
lucid
dne