| Vulnerability Name: | CVE-2006-2162 (CCN-26253) | ||||||||||||||||||||
| Assigned: | 2006-05-03 | ||||||||||||||||||||
| Published: | 2006-05-03 | ||||||||||||||||||||
| Updated: | 2018-10-03 | ||||||||||||||||||||
| Summary: | Buffer overflow in CGI scripts in Nagios 1.x before 1.4 and 2.x before 2.3 allows remote attackers to execute arbitrary code via a negative content length (Content-Length) HTTP header. Upgrade to versions 1.4 and 2.3 | ||||||||||||||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||||||||||||||
| Vulnerability Type: | CWE-Other | ||||||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2006-2162 Source: CCN Type: SA19991 Nagios Content-Length Handling Buffer Overflow Vulnerability Source: SECUNIA Type: UNKNOWN 19991 Source: SECUNIA Type: UNKNOWN 19998 Source: SECUNIA Type: UNKNOWN 20013 Source: SECUNIA Type: UNKNOWN 20215 Source: SECUNIA Type: UNKNOWN 20247 Source: DEBIAN Type: UNKNOWN DSA-1072 Source: DEBIAN Type: DSA-1072 nagios -- buffer overflow Source: CCN Type: GLSA-200605-07 Nagios: Buffer overflow Source: GENTOO Type: UNKNOWN GLSA-200605-07 Source: CCN Type: Nagios Web site Nagios: Home Source: CCN Type: Nagios Changelog Nagios: Changelog Source: CONFIRM Type: UNKNOWN http://www.nagios.org/development/changelog.php Source: SUSE Type: UNKNOWN SUSE-SR:2006:011 Source: CCN Type: OSVDB ID: 25434 Nagios Negative Content-Length HTTP Header Overflow Source: CCN Type: OSVDB ID: 25543 Nagios Content-Length HTTP Header Integer Overflow Source: BID Type: UNKNOWN 17879 Source: CCN Type: BID-17879 Nagios Remote Negative Content-Length Buffer Overflow Vulnerability Source: CCN Type: USN-282-1 nagios vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-1662 Source: XF Type: UNKNOWN nagios-multiple-scripts-bo(26253) Source: XF Type: UNKNOWN nagios-multiple-scripts-bo(26253) Source: CONFIRM Type: UNKNOWN https://sourceforge.net/mailarchive/forum.php?thread_id=10297806&forum_id=7890 Source: UBUNTU Type: UNKNOWN USN-282-1 Source: SUSE Type: SUSE-SR:2006:011 SUSE Security Summary Report | ||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
| BACK | |||||||||||||||||||||