Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 501690 (CVE-2014-1878) - <net-analyzer/icinga-{1.9.5,1.10.3} : "cmd_submitf()" Buffer Overflow Vulnerability (CVE-2014-1878)
Summary: <net-analyzer/icinga-{1.9.5,1.10.3} : "cmd_submitf()" Buffer Overflow Vulnera...
Status: RESOLVED FIXED
Alias: CVE-2014-1878
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/57024/
Whiteboard: ~2 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-02-18 13:46 UTC by Agostino Sarubbo
Modified: 2014-02-28 10:03 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-02-18 13:46:12 UTC
From ${URL} :

Description

A vulnerability has been reported in Icinga, which can be exploited by malicious users to cause a DoS 
(Denial of Service) or potentially compromise a vulnerable system.

The vulnerability is caused due to a boundary error in the "cmd_submitf()" function (cgi/cmd.c) and can be 
exploited to cause a stack-based buffer overflow.

Successful exploitation may allow execution of arbitrary code.

The vulnerability is reported in versions prior to 1.10.3, 1.9.5, and 1.8.6.


Solution:
Update to version 1.10.3, 1.9.5, or 1.8.6.

Provided and/or discovered by:
The vendor credits the GitHub security team and Dirkjan Bussink.

Original Advisory:
https://www.icinga.org/2014/02/11/bugfix-releases-1-10-3-1-9-5-1-8-6/


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2014-02-19 18:17:47 UTC
CVE-2014-1878

fixed in 1.10.3 / 1.9.5
Comment 2 Sergey Popov gentoo-dev 2014-02-28 10:03:18 UTC
There is no stable versions of icinga in tree. Also, there is no affected ones.

Closing as noglsa