Vulnerability Name:

CVE-2012-6096 (CCN-80618)

Assigned:2012-12-09
Published:2012-12-09
Updated:2013-06-05
Summary:Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1.8.4, might allow remote attackers to execute arbitrary code via a long (1) host_name variable (host parameter) or (2) svc_description variable.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
6.2 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-119
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: Full-disclosure Mailing List, Sun Dec 09 2012
Nagios Core 3.4.3: Stack based buffer overflow in web interface

Source: MITRE
Type: CNA
CVE-2012-6096

Source: FULLDISC
Type: UNKNOWN
20121209 Nagios Core 3.4.3: Stack based buffer overflow in web interface

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2013:0140

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2013:0169

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2013:0188

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2013:0206

Source: CCN
Type: SA51537
Nagios history.cgi "get_history()" Buffer Overflow Vulnerability

Source: CCN
Type: SA51863
Icinga history.cgi "show_history()" Buffer Overflow Vulnerability

Source: SECUNIA
Type: Vendor Advisory
51863

Source: DEBIAN
Type: UNKNOWN
DSA-2616

Source: DEBIAN
Type: UNKNOWN
DSA-2653

Source: DEBIAN
Type: DSA-2616
nagios3 -- buffer overflow in CGI scripts

Source: DEBIAN
Type: DSA-2653
icinga -- buffer overflow

Source: EXPLOIT-DB
Type: Exploit
24084

Source: EXPLOIT-DB
Type: Exploit
24159

Source: CCN
Type: Icinga Web site
Icinga

Source: CCN
Type: Nagios Web Site
Nagios

Source: CONFIRM
Type: UNKNOWN
http://www.nagios.org/projects/nagioscore/history/core-3x

Source: OSVDB
Type: UNKNOWN
89170

Source: BID
Type: Exploit
56879

Source: CCN
Type: BID-56879
Nagios Core 'get_history()' Function Stack Based Buffer Overflow Vulnerability

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.redhat.com/show_bug.cgi?id=893269

Source: CONFIRM
Type: Vendor Advisory
https://dev.icinga.org/issues/3532

Source: XF
Type: UNKNOWN
nagios-history-bo(80618)

Source: CCN
Type: Packet Storm Web site
Nagios 3.x Remote Command Execution

Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [01-13-2013]

Source: CONFIRM
Type: UNKNOWN
https://www.icinga.org/2013/01/14/icinga-1-6-2-1-7-4-1-8-4-released/

Source: CCN
Type: Rapid7 Vulnerability and Exploit Database [05-30-2018]
Nagios3 history.cgi Host Command Execution

Vulnerable Configuration:Configuration 1:
  • cpe:/a:nagios:nagios:3.0:*:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0:alpha1:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0:alpha2:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0:alpha3:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0:alpha4:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0:alpha5:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0:beta1:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0:beta2:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0:beta3:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0:beta4:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0:beta5:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0:beta6:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0:beta7:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0:rc1:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0:rc2:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0:rc3:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.0.6:*:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:3.4.2:*:*:*:*:*:*:*
  • OR cpe:/a:nagios:nagios:*:*:*:*:*:*:*:* (Version <= 3.4.3)

  • Configuration 2:
  • cpe:/a:icinga:icinga:1.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:icinga:icinga:1.6.1:*:*:*:*:*:*:*
  • OR cpe:/a:icinga:icinga:1.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:icinga:icinga:1.7.1:*:*:*:*:*:*:*
  • OR cpe:/a:icinga:icinga:1.7.2:*:*:*:*:*:*:*
  • OR cpe:/a:icinga:icinga:1.7.3:*:*:*:*:*:*:*
  • OR cpe:/a:icinga:icinga:1.8.0:*:*:*:*:*:*:*
  • OR cpe:/a:icinga:icinga:1.8.1:*:*:*:*:*:*:*
  • OR cpe:/a:icinga:icinga:1.8.2:*:*:*:*:*:*:*
  • OR cpe:/a:icinga:icinga:1.8.3:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:nagios:nagios_core:3.4.3:*:*:*:*:*:*:*
  • OR cpe:/a:icinga:icinga:1.6.1:*:*:*:*:*:*:*
  • OR cpe:/a:icinga:icinga:1.7.3:*:*:*:*:*:*:*
  • OR cpe:/a:icinga:icinga:1.8.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:42403
    P
    Security update for qemu (Important)
    2022-07-04
    oval:org.opensuse.security:def:20126096
    V
    CVE-2012-6096
    2022-06-30
    oval:org.opensuse.security:def:112426
    P
    icinga-1.13.3-2.4 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:26222
    P
    Security update for virglrenderer (Important) (in QA)
    2022-01-17
    oval:org.opensuse.security:def:26224
    P
    Security update for libvirt (Important)
    2022-01-05
    oval:org.opensuse.security:def:26175
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:31713
    P
    Security update for clamav (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:31714
    P
    Security update for webkit2gtk3 (Important)
    2021-12-01
    oval:org.opensuse.security:def:32216
    P
    Security update for MozillaFirefox (Important)
    2021-11-17
    oval:org.opensuse.security:def:105932
    P
    icinga-1.13.3-2.4 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:26138
    P
    Security update for python-urllib3 (Moderate)
    2021-09-29
    oval:org.opensuse.security:def:31680
    P
    Security update for transfig (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:32177
    P
    Security update for bind (Moderate)
    2021-08-30
    oval:org.opensuse.security:def:32167
    P
    Security update for openssl (Important)
    2021-08-24
    oval:org.opensuse.security:def:32959
    P
    Security update for libsolv (Important)
    2021-06-28
    oval:org.opensuse.security:def:26081
    P
    Security update for libgcrypt (Important)
    2021-06-24
    oval:org.opensuse.security:def:26082
    P
    Security update for openexr (Important)
    2021-06-24
    oval:org.opensuse.security:def:32128
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-06-18
    oval:org.opensuse.security:def:26071
    P
    Security update for the Linux Kernel (Important)
    2021-06-09
    oval:org.opensuse.security:def:42654
    P
    nagios-3.0.6-1.25.36.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36247
    P
    nagios-3.0.6-1.25.36.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:26070
    P
    Security update for spice (Important)
    2021-06-08
    oval:org.opensuse.security:def:36521
    P
    nagios-3.0.6-1.25.36.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32920
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:32080
    P
    Security update for the Linux Kernel (Live Patch 31 for SLE 12 SP3) (Important)
    2021-04-28
    oval:org.opensuse.security:def:32072
    P
    Security update for xen (Important)
    2021-04-19
    oval:org.opensuse.security:def:32282
    P
    Security update for wavpack (Important)
    2021-03-24
    oval:org.opensuse.security:def:31725
    P
    Security update for openvswitch (Important)
    2021-02-12
    oval:org.opensuse.security:def:32238
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-02-10
    oval:org.opensuse.security:def:26146
    P
    Security update for python3 (Important)
    2021-02-08
    oval:org.opensuse.security:def:26122
    P
    Security update for python-urllib3 (Moderate)
    2021-02-03
    oval:org.opensuse.security:def:25971
    P
    Security update for fontforge (Moderate)
    2020-12-04
    oval:org.opensuse.security:def:35996
    P
    nagios-3.0.6-1.25.28.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:31474
    P
    Security update for procmail (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27519
    P
    nagios on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25797
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:31916
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26959
    P
    libnewt0_52 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31931
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:26514
    P
    LibVNCServer on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32379
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25557
    P
    Security update for transfig (Low)
    2020-12-01
    oval:org.opensuse.security:def:26647
    P
    w3m on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33171
    P
    libpixman-1-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31462
    P
    Security update for postgresql94 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26846
    P
    xterm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31772
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26277
    P
    Security update for libreoffice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26000
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26426
    P
    Security update for singularity (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27210
    P
    libpulse-browse0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25545
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26412
    P
    Security update for tor (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32489
    P
    apache2-mod_php5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25830
    P
    Security update for libimobiledevice, usbmuxd (Important)
    2020-12-01
    oval:org.opensuse.security:def:26788
    P
    nagios-plugins on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31548
    P
    Security update for sblim-sfcb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25808
    P
    Security update for LibreOffice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26994
    P
    nagios on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32023
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26528
    P
    bzip2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26274
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32428
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:25621
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:26700
    P
    freetype2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33210
    P
    nagios on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31463
    P
    Security update for postgresql94 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27484
    P
    libsndfile-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25796
    P
    Security update for util-linux (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31829
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:26321
    P
    Security update for kcoreaddons (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31799
    P
    Security update for SDL (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26475
    P
    Recommended update for enigmail (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32323
    P
    Security update for samba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27245
    P
    nagios on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25546
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26496
    P
    Security update for tmux (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32533
    P
    java-1_6_0-ibm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25887
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:26802
    P
    pcsc-lite on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26263
    P
    Security update for libEMF (Important)
    2020-12-01
    oval:org.opensuse.security:def:25872
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:26373
    P
    Security update for ffmpeg (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26572
    P
    kdelibs4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26355
    P
    Security update for erlang (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32467
    P
    Security update for xorg-x11-libs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25749
    P
    Security update for pidgin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26749
    P
    libgtop on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:26016
    P
    SUSE-SU-2013:0358-1 -- Security update for nagios
    2014-09-08
    oval:org.mitre.oval:def:19990
    P
    DSA-2616-1 nagios3 - buffer overflow vulnerability
    2014-06-23
    oval:org.mitre.oval:def:18427
    P
    DSA-2653-1 icinga - buffer overflow
    2014-06-23
    oval:com.ubuntu.xenial:def:201260960000000
    V
    CVE-2012-6096 on Ubuntu 16.04 LTS (xenial) - negligible.
    2013-01-22
    oval:com.ubuntu.precise:def:20126096000
    V
    CVE-2012-6096 on Ubuntu 12.04 LTS (precise) - negligible.
    2013-01-22
    oval:com.ubuntu.trusty:def:20126096000
    V
    CVE-2012-6096 on Ubuntu 14.04 LTS (trusty) - negligible.
    2013-01-22
    oval:com.ubuntu.xenial:def:20126096000
    V
    CVE-2012-6096 on Ubuntu 16.04 LTS (xenial) - negligible.
    2013-01-22
    BACK
    nagios nagios 3.0
    nagios nagios 3.0 alpha1
    nagios nagios 3.0 alpha2
    nagios nagios 3.0 alpha3
    nagios nagios 3.0 alpha4
    nagios nagios 3.0 alpha5
    nagios nagios 3.0 beta1
    nagios nagios 3.0 beta2
    nagios nagios 3.0 beta3
    nagios nagios 3.0 beta4
    nagios nagios 3.0 beta5
    nagios nagios 3.0 beta6
    nagios nagios 3.0 beta7
    nagios nagios 3.0 rc1
    nagios nagios 3.0 rc2
    nagios nagios 3.0 rc3
    nagios nagios 3.0.1
    nagios nagios 3.0.2
    nagios nagios 3.0.3
    nagios nagios 3.0.4
    nagios nagios 3.0.5
    nagios nagios 3.0.6
    nagios nagios 3.1.0
    nagios nagios 3.1.1
    nagios nagios 3.1.2
    nagios nagios 3.2.0
    nagios nagios 3.2.1
    nagios nagios 3.2.2
    nagios nagios 3.2.3
    nagios nagios 3.3.1
    nagios nagios 3.4.0
    nagios nagios 3.4.1
    nagios nagios 3.4.2
    nagios nagios *
    icinga icinga 1.6.0
    icinga icinga 1.6.1
    icinga icinga 1.7.0
    icinga icinga 1.7.1
    icinga icinga 1.7.2
    icinga icinga 1.7.3
    icinga icinga 1.8.0
    icinga icinga 1.8.1
    icinga icinga 1.8.2
    icinga icinga 1.8.3
    nagios nagios core 3.4.3
    icinga icinga 1.6.1
    icinga icinga 1.7.3
    icinga icinga 1.8.3