Back

LOW

nagios-plugins: check_dhcp Arbitrary Option File Read

Published Dec 5, 2014

Description

lib/parse_ini.c in Nagios Plugins 2.0.2 allows local users to obtain sensitive information via a symlink attack on the configuration file in the extra-opts flag. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4701.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of nagios-plugins as shipped with Red Hat Enterprise Linux OpenStack Platform.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 5, 2014
Updated Aug 6, 2024
Reserved Jun 30, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date May 16, 2014