CVE-2018-13441
MEDIUMNagios < 4.4.1 - Denial of Service via qh_help NULL Pointer Dereference
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-13441. PoCs published by Fakhri Zulkifli.
AI-analyzed exploit summary This exploit demonstrates a NULL pointer dereference vulnerability in Nagios Core 4.4.1 and earlier, allowing local denial-of-service attacks via crafted payloads sent to a UNIX socket. The PoC includes specific commands for three CVEs (CVE-2018-13458, CVE-2018-13457, CVE-2018-13441).
Description
qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.
Exploits (1)
This exploit demonstrates a NULL pointer dereference vulnerability in Nagios Core 4.4.1 and earlier, allowing local denial-of-service attacks via crafted payloads sent to a UNIX socket. The PoC includes specific commands for three CVEs (CVE-2018-13458, CVE-2018-13457, CVE-2018-13441).
References (6)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H