vendor:
Nagios Core
by:
Fakhri Zulkifli
5.5
CVSS
MEDIUM
NULL pointer dereference vulnerability
476
CWE
Product Name: Nagios Core
Affected Version From: 4.4.1
Affected Version To: 4.4.1
Patch Exists: YES
Related CWE: CVE-2018-13458, CVE-2018-13457, CVE-2018-13441
CPE: a:nagios:nagios_core
Platforms Tested: 4.4.1
2018
Nagios Core Multiple Local Denial of Service
qh_core, qh_help, and qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.
Mitigation:
Upgrade to the latest version of Nagios Core