6.3
CVSSv2

CVE-2013-4214

Published: 23/11/2013 Updated: 13/02/2023
CVSS v2 Base Score: 6.3 | Impact Score: 9.2 | Exploitability Score: 3.4
VMScore: 561
Vector: AV:L/AC:M/Au:N/C:N/I:C/A:C

Vulnerability Summary

rss-newsfeed.php in Nagios Core 3.4.4, 3.5.1, and previous versions, when MAGPIE_CACHE_ON is set to 1, allows local users to overwrite arbitrary files via a symlink attack on /tmp/magpie_cache.

Vulnerable Product Search on Vulmon Subscribe to Product

nagios nagios 3.4.4

redhat openstack 3.0

nagios nagios

Vendor Advisories

Synopsis Moderate: nagios security update Type/Severity Security Advisory: Moderate Topic Updated nagios packages that fix two security issues are now availablefor Red Hat OpenStack 30The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnerability Scoring S ...
Debian Bug report logs - #719056 nagios3: CVE-2013-4214: html/rss-newsfeedphp insecure temporary file usage Package: nagios3-cgi; Maintainer for nagios3-cgi is Debian Nagios Maintainer Group <pkg-nagios-devel@listsaliothdebianorg>; Source for nagios3-cgi is src:nagios3 (PTS, buildd, popcon) Reported by: Salvatore Bonacco ...
Multiple off-by-one errors in Nagios Core 351, 402, and earlier, and Icinga before 185, 19 before 194, and 110 before 1102 allow remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list to the process_cgivars function ...
rss-newsfeedphp in Nagios Core 344, 351, and earlier, when MAGPIE_CACHE_ON is set to 1, allows local users to overwrite arbitrary files via a symlink attack on /tmp/magpie_cache ...