CVE-2013-7106
Description
Multiple stack-based buffer overflows in Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long string to the (1) display_nav_table, (2) page_limit_selector, (3) print_export_link, or (4) page_num_selector function in cgi/cgiutils.c; (5) status_page_num_selector function in cgi/status.c; or (6) display_command_expansion function in cgi/config.c. NOTE: this can be exploited without authentication by leveraging CVE-2013-7107.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| icinga | icinga | {"endIncluding":"1.8.4"} | |
| icinga | icinga | 0.8.0 | |
| icinga | icinga | 0.8.1 | |
| icinga | icinga | 0.8.2 | |
| icinga | icinga | 0.8.3 | |
| icinga | icinga | 0.8.4 | |
| icinga | icinga | 1.0 | |
| icinga | icinga | 1.0.1 | |
| icinga | icinga | 1.0.2 | |
| icinga | icinga | 1.0.3 | |
| icinga | icinga | 1.2.0 | |
| icinga | icinga | 1.2.1 | |
| icinga | icinga | 1.3.0 | |
| icinga | icinga | 1.3.1 | |
| icinga | icinga | 1.4.0 | |
| icinga | icinga | 1.4.1 | |
| icinga | icinga | 1.6.0 | |
| icinga | icinga | 1.6.1 | |
| icinga | icinga | 1.6.2 | |
| icinga | icinga | 1.7.0 | |
| icinga | icinga | 1.7.1 | |
| icinga | icinga | 1.7.2 | |
| icinga | icinga | 1.7.3 | |
| icinga | icinga | 1.7.4 | |
| icinga | icinga | 1.8.0 | |
| icinga | icinga | 1.8.1 | |
| icinga | icinga | 1.8.2 | |
| icinga | icinga | 1.8.3 | |
| icinga | icinga | 1.9.0 | |
| icinga | icinga | 1.9.1 | |
| icinga | icinga | 1.9.2 | |
| icinga | icinga | 1.9.3 | |
| icinga | icinga | 1.10.0 | |
| icinga | icinga | 1.10.1 | |
References
- http://www.openwall.com/lists/oss-security/2013/12/16/4
- https://dev.icinga.org/issues/5250
- https://www.icinga.org/2013/12/17/icinga-security-releases-1-10-2-1-9-4-1-8-5/
- http://www.openwall.com/lists/oss-security/2013/12/16/4
- https://dev.icinga.org/issues/5250
- https://www.icinga.org/2013/12/17/icinga-security-releases-1-10-2-1-9-4-1-8-5/
CWEs
CWE-119
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.