Skip to navigation

CVE Database

CVE-2013-1362

Impact: Important
Public: 2013-02-21
CWE: CWE-78
Bugzilla: 916947: CVE-2013-1362 Nagios NRPE: nagios metacharacter filtering omission

Details

The MITRE CVE dictionary describes this issue as:

Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.

Find out more about CVE-2013-1362 from the MITRE CVE dictionary and NIST NVD.

CVSS v2 metrics

NOTE: The following CVSS v2 metrics and score provided are preliminary and subject to review.

Base Score: 7.5
Base Metrics: AV:N/AC:L/Au:N/C:P/I:P/A:P
Access Vector: Network
Access Complexity: Low
Authentication: None
Confidentiality Impact: Partial
Integrity Impact: Partial
Availability Impact: Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat security errata

Platform Errata Release Date

External References

http://seclists.org/bugtraq/2013/Feb/119

http://www.occamsec.com/vulnerabilities.html#nagios_metacharacter_vulnerability

This page is generated automatically and has not been checked for errors or omissions.

For clarification or corrections please contact the Red Hat Security Response Team.