ID:6399 - Exploit for Null pointer dereference in Nagios - CVE-2018-13441

 
Main Vulnerability Database Exploits ID:6399 - Exploit for Null pointer dereference in Nagios - CVE-2018-13441

ID:6399 - Exploit for Null pointer dereference in Nagios - CVE-2018-13441

Published: June 17, 2021


Vulnerability identifier: #VU14020
Vulnerability risk: Low
CVE-ID: CVE-2018-13441
CWE-ID: CWE-476
Exploitation vector: Local access
Vulnerable software:
Nagios

Link to public exploit:


Vulnerability description

The vulnerability allows a local attacker to cause DoS condition on the target system.

The vulnerability exists in qh_help due to an error when handling malicious input. A local attacker can send a specially crafted payload to the listening UNIX socket, trigger NULL pointer dereference and cause the service to crash.


Remediation

Install update from vendor's website.