CVE-2014-1878

Stack-based buffer overflow in the cmd_submitf function in cgi/cmd.c in Nagios Core, possibly 4.0.3rc1 and earlier, and Icinga before 1.8.6, 1.9 before 1.9.5, and 1.10 before 1.10.3 allows remote attackers to cause a denial of service (segmentation fault) via a long message to cmd.cgi.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
VendorProductVersion
icingaicinga
𝑥
≤ 1.8.5
icingaicinga
1.8.0
icingaicinga
1.8.1
icingaicinga
1.8.2
icingaicinga
1.8.3
icingaicinga
1.8.4
icingaicinga
1.9.0
icingaicinga
1.9.1
icingaicinga
1.9.2
icingaicinga
1.9.3
icingaicinga
1.9.4
icingaicinga
1.10.0
icingaicinga
1.10.1
icingaicinga
1.10.2
nagiosnagios
𝑥
≤ 4.0.3
nagiosnagios
4.0.0:beta1
nagiosnagios
4.0.0:beta2
nagiosnagios
4.0.0:beta3
nagiosnagios
4.0.0:beta4
nagiosnagios
4.0.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
icinga
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
dne
saucy
ignored
quantal
ignored
precise
ignored
lucid
dne
nagios3
zesty
Fixed 3.5.1.dfsg-2.1ubuntu5
released
yakkety
Fixed 3.5.1.dfsg-2.1ubuntu3.1
released
xenial
Fixed 3.5.1.dfsg-2.1ubuntu1.1
released
wily
ignored
vivid
ignored
utopic
ignored
trusty
Fixed 3.5.1-1ubuntu1.1
released
saucy
ignored
quantal
ignored
precise
ignored
lucid
ignored