Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Gentoo Local Security Checks >> [GLSA-200605-07] Nagios: Buffer overflow


Vulnerability Assessment Details

[GLSA-200605-07] Nagios: Buffer overflow

Vulnerability Assessment Summary
Nagios: Buffer overflow

Detailed Explanation for this Vulnerability Assessment
The remote host is affected by the vulnerability described in GLSA-200605-07
(Nagios: Buffer overflow)


Sebastian Krahmer of the SuSE security team discovered a buffer
overflow vulnerability in the handling of a negative HTTP
Content-Length header.

Impact

A buffer overflow in Nagios CGI scripts under certain web servers
permits remote attackers to execute arbitrary code via a negative
content length HTTP header.

Workaround

There is no known workaround at this time.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2162


Solution:
All Nagios users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-analyzer/nagios-core-1.4"


Network Security Threat Level: High


Networks Security ID:

Vulnerability Assessment Copyright: (C) 2006 Michel Arboi

Cables, Connectors

HP Elitebook 840 G2 14" Laptop Core i5-5300U 2.3GHz 8GB 128GB SSD w/ Win 10 Pro
$309.99
HP Elitebook 840 G2 14QTY 1x Intel Xeon E5-2667 V3 CPU 8-Cores 3.2 Ghz 20MB Cache LGA2011-3 SR203
$1290.0
QTY 1x Intel Xeon E5-2667 V3 CPU 8-Cores 3.2 Ghz 20MB Cache LGA2011-3 SR203 pictureIntel CPU Core i7 4790K 4.00GHz 8M LGA1150 LGA-1150 Devil's Canyon UnLocked NEW
$590.0
Intel CPU Core i7 4790K 4.00GHz 8M LGA1150 LGA-1150 Devil's Canyon UnLocked NEW pictureLenovo - Flex 3 2-in-1 14" Touch-Screen Laptop - Intel Core i7 - 8GB Memory -...
$849.99
Lenovo - Flex 3 2-in-1 14


Discussions

No Discussions have been posted on this vulnerability.