CVE-2007-5198
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 8.0%
from disclosure to weapon0 days
Published on NVDOct 4
1st PoCJul 16
exploitation probability
8.0%top 6% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Buffer overflow in the redir function in check_http.c in Nagios Plugins before 1.4.10, when running with the -f (follow) option, allows remote web servers to execute arbitrary code via Location header responses (redirects) with a large number of leading "L" characters.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/30646⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://bugs.gentoo.org/show_bug.cgi?id=194178http://secunia.com/advisories/27124http://secunia.com/advisories/27362http://secunia.com/advisories/27609http://secunia.com/advisories/27965http://secunia.com/advisories/28930http://secunia.com/advisories/29862http://security.gentoo.org/glsa/glsa-200711-11.xmlhttp://sourceforge.net/forum/forum.php?forum_id=740172http://sourceforge.net/tracker/index.php?func=detail&aid=1687867&group_id=29880&atid=397597http://sourceforge.net/tracker/index.php?func=detail&aid=1813346&group_id=29880&atid=397597https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00249.html