Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list to the process_cgivars function in (1) avail.c, (2) cmd.c, (3) config.c, (4) extinfo.c, (5) histogram.c, (6) notifications.c, (7) outages.c, (8) status.c, (9) statusmap.c, (10) summary.c, and (11) trends.c in cgi/, which triggers a heap-based buffer over-read.
| Software | From | Fixed in |
|---|---|---|
| nagios / nagios | 3.0-alpha3 | 3.0-alpha3.x |
| nagios / nagios | 3.1.2 | 3.1.2.x |
| nagios / nagios | 3.0-rc3 | 3.0-rc3.x |
| nagios / nagios | 3.0-beta4 | 3.0-beta4.x |
| nagios / nagios | 3.0-alpha5 | 3.0-alpha5.x |
| nagios / nagios | 3.2.2 | 3.2.2.x |
| nagios / nagios | 3.2.0 | 3.2.0.x |
| nagios / nagios | 3.1.1 | 3.1.1.x |
| nagios / nagios | 3.0.6 | 3.0.6.x |
| nagios / nagios | 3.0-alpha2 | 3.0-alpha2.x |
| nagios / nagios | 3.0.1 | 3.0.1.x |
| nagios / nagios | 3.0-beta5 | 3.0-beta5.x |
| nagios / nagios | 3.4.1 | 3.4.1.x |
| nagios / nagios | 3.0-rc1 | 3.0-rc1.x |
| nagios / nagios | 3.0.2 | 3.0.2.x |
| nagios / nagios | 3.1.0 | 3.1.0.x |
| nagios / nagios | 3.0-beta2 | 3.0-beta2.x |
| nagios / nagios | 3.0-beta7 | 3.0-beta7.x |
| nagios / nagios | 3.0-rc2 | 3.0-rc2.x |
| nagios / nagios | - | 4.0.2.x |
| nagios / nagios | 3.4.2 | 3.4.2.x |
| nagios / nagios | 3.0 | 3.0.x |
| nagios / nagios | 3.4.3 | 3.4.3.x |
| nagios / nagios | 3.5.1 | 3.5.1.x |
| nagios / nagios | 3.0.4 | 3.0.4.x |
| nagios / nagios | 3.0-alpha1 | 3.0-alpha1.x |
| nagios / nagios | 3.0-beta6 | 3.0-beta6.x |
| nagios / nagios | 3.0-alpha4 | 3.0-alpha4.x |
| nagios / nagios | 3.2.1 | 3.2.1.x |
| nagios / nagios | 3.0-beta1 | 3.0-beta1.x |
| nagios / nagios | 3.0-beta3 | 3.0-beta3.x |
| nagios / nagios | 3.0.3 | 3.0.3.x |
| nagios / nagios | 3.2.3 | 3.2.3.x |
| nagios / nagios | 3.3.1 | 3.3.1.x |
| nagios / nagios | 3.0.5 | 3.0.5.x |
| nagios / nagios | 3.4.0 | 3.4.0.x |
| icinga / icinga | 0.8.1 | 0.8.1.x |
| icinga / icinga | 0.8.4 | 0.8.4.x |
| icinga / icinga | 1.9.2 | 1.9.2.x |
| icinga / icinga | 1.0.2 | 1.0.2.x |
| icinga / icinga | 1.9.3 | 1.9.3.x |
| icinga / icinga | 1.2.1 | 1.2.1.x |
| icinga / icinga | 0.8.3 | 0.8.3.x |
| icinga / icinga | 1.9.0 | 1.9.0.x |
| icinga / icinga | 1.6.1 | 1.6.1.x |
| icinga / icinga | 1.7.0 | 1.7.0.x |
| icinga / icinga | 0.8.0 | 0.8.0.x |
| icinga / icinga | 1.3.0 | 1.3.0.x |
| icinga / icinga | 1.7.4 | 1.7.4.x |
| icinga / icinga | 1.8.2 | 1.8.2.x |
| icinga / icinga | 1.8.0 | 1.8.0.x |
| icinga / icinga | 0.8.2 | 0.8.2.x |
| icinga / icinga | - | 1.8.4.x |
| icinga / icinga | 1.7.2 | 1.7.2.x |
| icinga / icinga | 1.0.3 | 1.0.3.x |
| icinga / icinga | 1.3.1 | 1.3.1.x |
| icinga / icinga | 1.4.0 | 1.4.0.x |
| icinga / icinga | 1.7.3 | 1.7.3.x |
| icinga / icinga | 1.0 | 1.0.x |
| icinga / icinga | 1.8.3 | 1.8.3.x |
| icinga / icinga | 1.8.1 | 1.8.1.x |
| icinga / icinga | 1.6.0 | 1.6.0.x |
| icinga / icinga | 1.0-rc1 | 1.0-rc1.x |
| icinga / icinga | 1.6.2 | 1.6.2.x |
| icinga / icinga | 1.9.1 | 1.9.1.x |
| icinga / icinga | 1.4.1 | 1.4.1.x |
| icinga / icinga | 1.10.1 | 1.10.1.x |
| icinga / icinga | 1.2.0 | 1.2.0.x |
| icinga / icinga | 1.0.1 | 1.0.1.x |
| icinga / icinga | 1.7.1 | 1.7.1.x |
| icinga / icinga | 1.10.0 | 1.10.0.x |