peter bassill · operator
$ cve CVE-2013-7108 JSON

CVE-2013-7108 EXPLOIT

5.5
MEDIUM · CVSS 2.0 · EPSS 59.5% (pctl 99)

Patch early

A public exploit exists.

Description

Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list to the process_cgivars function in (1) avail.c, (2) cmd.c, (3) config.c, (4) extinfo.c, (5) histogram.c, (6) notifications.c, (7) outages.c, (8) status.c, (9) statusmap.c, (10) summary.c, and (11) trends.c in cgi/, which triggers a heap-based buffer over-read.

Scoring

CVSS5.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:N/A:P
EPSS59.55% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2014-01-15
Last modified2026-06-17

Affected (2)

VendorProduct
icingaicinga
nagiosnagios

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD