FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

nagios-plugins -- Long Location Header Buffer Overflow Vulnerability

Affected packages
nagios-plugins < 1.4.10,1

Details

VuXML ID 7453c85d-7830-11dc-b4c8-0016179b2dd5
Discovery 2007-09-28
Entry 2007-10-11

A Secunia Advisory reports:

The vulnerability is caused due to a boundary error within the redir() function in check_http.c when processing HTTP Location: header information. This can be exploited to cause a buffer overflow by returning an overly long string in the "Location:" header to a vulnerable system.

References

CVE Name CVE-2007-5198
URL http://secunia.com/advisories/27124/
URL http://sourceforge.net/forum/forum.php?forum_id=740172