CVE-2014-4701

Related Vulnerabilities: CVE-2014-4701  

The check_dhcp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configuration files via the extra-opts flag, a different vulnerability than CVE-2014-4702.

The MITRE CVE dictionary describes this issue as:

The check_dhcp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configuration files via the extra-opts flag, a different vulnerability than CVE-2014-4702.

Find out more about CVE-2014-4701 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue did not affect the versions of nagios-plugins as shipped with Red Hat Enterprise Linux OpenStack Platform.

CVSS v2 metrics

NOTE: The following CVSS v2 metrics and score provided are preliminary and subject to review.

Base Score 4.4
Base Metrics AV:L/AC:M/Au:S/C:C/I:N/A:N
Access Vector Local
Access Complexity Medium
Authentication Single
Confidentiality Impact Complete
Integrity Impact None
Availability Impact None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Affected Packages State

Platform Package State
Red Hat Enterprise Linux OpenStack Platform 4.0 nagios-plugins Not affected
Red Hat Enterprise Linux OpenStack Platform 3.0 nagios-plugins Not affected