nrpe: heap-based buffer overflow due to a wrong integer type conversion
Published Mar 16, 2020
7.5
HIGHCVSS 3.1
EPSS 4.44%
Description
Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call.
Affected products
No data.
Configuration 1
- 3.2.1
Configuration 2
- 32
No data.
Red Hat Storage 3
nrpe
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Storage 3 | nrpe | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Nagios is considered deprecated. Nagios plugins and Nagios server are no longer maintained or supported. Refer following release notes for details: "https://access.redhat.com/documentation/en-us/red_hat_gluster_storage/3.5/html-single/3.5_release_notes/index". The older version of nrpe which was shipped with Red Hat Gluster Storage does not support v3 packet format.
Red Hat mitigation
There is no known mitigation for this issue, the flaw can only be resolved by applying updates.
References (7)
- https://access.redhat.com/security/cve/CVE-2020-6582 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1816813 Issue Tracking
- https://herolab.usd.de/security-advisories/ x_refsource_MISCThird Party Advisory
- https://herolab.usd.de/security-advisories/usd-2020-0001/ x_refsource_MISCExploitThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2DNGKXVDB43E3KQRA6W5QZT3Z46XZLQM/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2020-6582
- https://www.cve.org/CVERecord?id=CVE-2020-6582
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-6582 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1816813 | Issue Tracking | |
| https://herolab.usd.de/security-advisories/ | x_refsource_MISCThird Party Advisory | |
| https://herolab.usd.de/security-advisories/usd-2020-0001/ | x_refsource_MISCExploitThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2DNGKXVDB43E3KQRA6W5QZT3Z46XZLQM/ | vendor-advisoryx_refsource_FEDORA | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-6582 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-6582 |
Change history (0)
No recorded changes yet.