NULL Pointer Dereference Vulnerability in Nagios Core by Nagios Enterprises
CVE-2018-13458

5.5MEDIUM

Key Information:

Vendor

Nagios

Vendor
CVE Published:
12 July 2018

What is CVE-2018-13458?

A NULL pointer dereference vulnerability exists in the qh_core component of Nagios Core versions 4.4.1 and earlier. When an attacker sends a specially crafted payload to the UNIX socket that Nagios Core listens on, it can lead to a local denial-of-service condition, effectively causing the service to become unresponsive. This vulnerability highlights the need for stringent input validation and the importance of applying security patches promptly to mitigate potential exploitation risks.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2018-13458 : NULL Pointer Dereference Vulnerability in Nagios Core by Nagios Enterprises