Main
Vulnerability Database
Exploits
ID:6399 - Exploit for Null pointer dereference in Nagios - CVE-2018-13441
ID:6399 - Exploit for Null pointer dereference in Nagios - CVE-2018-13441
Published: June 17, 2021
Vulnerability identifier: #VU14020
Vulnerability risk: Low
CVE-ID: CVE-2018-13441
CWE-ID: CWE-476
Exploitation vector: Local access
Vulnerable software:
Nagios
Nagios
Link to public exploit:
Vulnerability description
The vulnerability allows a local attacker to cause DoS condition on the target system.
The vulnerability exists in qh_help due to an error when handling malicious input. A local attacker can send a specially crafted payload to the listening UNIX socket, trigger NULL pointer dereference and cause the service to crash.
Remediation
Install update from vendor's website.