Buffer overflow in the redir function in check_http.c in Nagios Plugins before 1.4.10, when running with the -f (follow) option, allows remote web servers to execute arbitrary code via Location header responses (redirects) with a large number of leading "L" characters.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade nagios-plugins | Dec 10, 2025 | Oct 11, 2007 |
| Gentoo Linux | — | Upgrade net-analyzer/nagios-plugins. | Oct 30, 2017 | Oct 4, 2007 |
| Suse | — | Upgrade nagios-pluginsUpgrade suse-releaseUpgrade nagios-plugins-extras | Feb 17, 2015 | Oct 4, 2007 |
| Ubuntu | — | Upgrade nagios-pluginsUpgrade nagios-plugins-basicUpgrade nagios-plugins-standard | Nov 8, 2024 | Oct 4, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub