APP: Nagios Remote Plugin Executor 2.13 Code Execution
This signature detects attempts to exploit a known vulnerability against Nagios NRPE 2.13. A successful attack can lead to arbitrary code execution.
Extended Description
Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.
Affected Products
Nagios remote_plug_in_executor
References
BugTraq: 58142
CVE: CVE-2013-1362
URL: http://www.nagios.org/news/77-news-announcements/345-nrpe-214-released
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Opensuse
Nagios
7.5