Vulnerability Description
lib/parse_ini.c in Nagios Plugins 2.0.2 allows local users to obtain sensitive information via a symlink attack on the configuration file in the extra-opts flag. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4701.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nagios | Nagios | 2.0.2 |
Related Weaknesses (CWE)
References
- http://nagios-plugins.org/nagios-plugins-2-0-3-released/PatchVendor Advisory
- http://seclists.org/fulldisclosure/2014/Jun/141Exploit
- http://www.openwall.com/lists/oss-security/2014/06/30/6
- http://www.securityfocus.com/bid/76810
- http://nagios-plugins.org/nagios-plugins-2-0-3-released/PatchVendor Advisory
- http://seclists.org/fulldisclosure/2014/Jun/141Exploit
- http://www.openwall.com/lists/oss-security/2014/06/30/6
- http://www.securityfocus.com/bid/76810
FAQ
What is CVE-2014-4703?
CVE-2014-4703 is a vulnerability with a CVSS score of 2.1 (LOW). lib/parse_ini.c in Nagios Plugins 2.0.2 allows local users to obtain sensitive information via a symlink attack on the configuration file in the extra-opts flag. NOTE: this vulnerability exists becau...
How severe is CVE-2014-4703?
CVE-2014-4703 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-4703?
Check the references section above for vendor advisories and patch information. Affected products include: Nagios Nagios.