CVE Vulnerabilities

CVE-2014-2913

Published: May 07, 2014 | Modified: Aug 06, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
7.5 IMPORTANT
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW

Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary commands via a newline character in the -a option to libexec/check_nrpe. NOTE: this issue is disputed by multiple parties. It has been reported that the vendor allows newlines as expected behavior. Also, this issue can only occur when the administrator enables the dont_blame_nrpe option in nrpe.conf despite the HIGH security risk warning within the comments

Affected Software

Name Vendor Start Version End Version
Remote_plugin_executor Nagios * 2.15 (including)
Opensuse Opensuse 11.4 (including) 11.4 (including)
Opensuse Opensuse 12.3 (including) 12.3 (including)
Opensuse Opensuse 13.1 (including) 13.1 (including)
Nagios-nrpe Ubuntu artful *
Nagios-nrpe Ubuntu bionic *
Nagios-nrpe Ubuntu cosmic *
Nagios-nrpe Ubuntu disco *
Nagios-nrpe Ubuntu eoan *
Nagios-nrpe Ubuntu groovy *
Nagios-nrpe Ubuntu hirsute *
Nagios-nrpe Ubuntu impish *
Nagios-nrpe Ubuntu kinetic *
Nagios-nrpe Ubuntu lucid *
Nagios-nrpe Ubuntu lunar *
Nagios-nrpe Ubuntu mantic *
Nagios-nrpe Ubuntu precise *
Nagios-nrpe Ubuntu quantal *
Nagios-nrpe Ubuntu saucy *
Nagios-nrpe Ubuntu trusty *
Nagios-nrpe Ubuntu upstream *
Nagios-nrpe Ubuntu utopic *
Nagios-nrpe Ubuntu vivid *
Nagios-nrpe Ubuntu wily *
Nagios-nrpe Ubuntu yakkety *
Nagios-nrpe Ubuntu zesty *

References