#VU14020 Null pointer dereference in Nagios - CVE-2018-13441
Published: July 23, 2018 / Updated: June 17, 2021
Nagios
nagios.org
Description
The vulnerability allows a local attacker to cause DoS condition on the target system.
The vulnerability exists in qh_help due to an error when handling malicious input. A local attacker can send a specially crafted payload to the listening UNIX socket, trigger NULL pointer dereference and cause the service to crash.