Vulnerability Report

CVE-2012-6096

Title: Nagios RCE

Memory Corruption

Proof Of Concept

PoC Available for CVE-2012-6096

CWE Category CWE-119
Published Date Jan 22, 2013
Modified Date Jun 16, 2026
Exploit Status Available
Score 7.5 CVSS v2.0
Exploit Probability (EPSS)
66.45%

Vulnerability Summary

CVE-2012-6096: Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1.8.4, might allow remote attackers to execute arbitrary code via a long (1) host_name variable (host parameter) or (2) svc_description variable.

Impacted Vendors

Reference Links

http://lists.grok.org.uk/pipermail/full-disclosure/2012-December/089125.html http://lists.opensuse.org/opensuse-updates/2013-01/msg00033.html http://lists.opensuse.org/opensuse-updates/2013-01/msg00060.html http://lists.opensuse.org/opensuse-updates/2013-01/msg00077.html http://lists.opensuse.org/opensuse-updates/2013-01/msg00088.html http://secunia.com/advisories/51863 http://www.debian.org/security/2013/dsa-2616 http://www.debian.org/security/2013/dsa-2653 http://www.exploit-db.com/exploits/24084 http://www.exploit-db.com/exploits/24159 http://www.nagios.org/projects/nagioscore/history/core-3x http://www.osvdb.org/89170 http://www.securityfocus.com/bid/56879 https://bugzilla.redhat.com/show_bug.cgi?id=893269 https://dev.icinga.org/issues/3532 https://www.icinga.org/2013/01/14/icinga-1-6-2-1-7-4-1-8-4-released/ http://lists.grok.org.uk/pipermail/full-disclosure/2012-December/089125.html http://lists.opensuse.org/opensuse-updates/2013-01/msg00033.html http://lists.opensuse.org/opensuse-updates/2013-01/msg00060.html http://lists.opensuse.org/opensuse-updates/2013-01/msg00077.html http://lists.opensuse.org/opensuse-updates/2013-01/msg00088.html http://secunia.com/advisories/51863 http://www.debian.org/security/2013/dsa-2616 http://www.debian.org/security/2013/dsa-2653 http://www.exploit-db.com/exploits/24084 http://www.exploit-db.com/exploits/24159 http://www.nagios.org/projects/nagioscore/history/core-3x http://www.osvdb.org/89170 http://www.securityfocus.com/bid/56879 https://bugzilla.redhat.com/show_bug.cgi?id=893269 https://dev.icinga.org/issues/3532 https://www.icinga.org/2013/01/14/icinga-1-6-2-1-7-4-1-8-4-released/
CVSS v2.0
Source Entity [email protected]
Severity HIGH
7.5
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:N/AC:L/Au:N/C:P/I:P/A:P

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2012-6096 Exploits & PoCs (Proof Of Concept)

Exploit-DB https://www.exploit-db.com/exploits/24159
View Code
Exploit-DB https://www.exploit-db.com/exploits/24084
View Code
MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected Stack

No specific products linked.