CVE-2008-7313
published 2017-03-31CVE-2008-7313: The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
PriorityP357critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.54%
90.5th percentile
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libphp-snoopy | < libphp-snoopy 2.0.0-1 (bookworm) | libphp-snoopy 2.0.0-1 (bookworm) |
| nagios | nagios | <= 4.2.3 | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
snoopy: incomplete fixes for command execution flaws
vendor_redhat·2014-07-03·CVSS 10.0
CVE-2008-7313 [CRITICAL] snoopy: incomplete fixes for command execution flaws
snoopy: incomplete fixes for command execution flaws
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
Various command-execution flaws were found in the Snoopy library included with Nagios. These flaws allowed remote attackers to execute arbitrary commands by manipulating Nagios HTTP headers.
Package: nagios (Red Hat OpenStack Platform 3) - Will not fix
Package: nagios (Red Hat OpenStack Platform 4) - Will not fix
Package: nagios (Red Hat Storage 2.1) - Will not fix
Package: nagios (Red Hat Storage 3.0) - Will not fix
Debian
CVE-2008-7313: libphp-snoopy - The _httpsrequest function in Snoopy allows remote attackers to execute arbitrar...
vendor_debian·2008·CVSS 10.0
CVE-2008-7313 [CRITICAL] CVE-2008-7313: libphp-snoopy - The _httpsrequest function in Snoopy allows remote attackers to execute arbitrar...
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
Scope: local
bookworm: resolved (fixed in 2.0.0-1)
bullseye: resolved (fixed in 2.0.0-1)
sid: resolved (fixed in 2.0.0-1)
GHSA
GHSA-wr36-qh3g-7h4v: The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2008-7313 [CRITICAL] CWE-77 GHSA-wr36-qh3g-7h4v: The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
OSV
CVE-2008-7313: The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands
osv·2017-03-31·CVSS 10.0
CVE-2008-7313 [CRITICAL] CVE-2008-7313: The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 wordpress-mu: snoopy: incomplete fixes for command execution flaws [epel-5]
bugzilla·2014-07-21·CVSS 9.8
CVE-2014-5009 [CRITICAL] CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 wordpress-mu: snoopy: incomplete fixes for command execution flaws [epel-5]
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 wordpress-mu: snoopy: incomplete fixes for command execution flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when a
Bugzilla
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 sahana: snoopy: incomplete fixes for command execution flaws [epel-5]
bugzilla·2014-07-21·CVSS 9.8
CVE-2014-5009 [CRITICAL] CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 sahana: snoopy: incomplete fixes for command execution flaws [epel-5]
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 sahana: snoopy: incomplete fixes for command execution flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availab
Bugzilla
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 nagios: snoopy: incomplete fixes for command execution flaws [epel-all]
bugzilla·2014-07-21·CVSS 9.8
CVE-2014-5009 [CRITICAL] CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 nagios: snoopy: incomplete fixes for command execution flaws [epel-all]
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 nagios: snoopy: incomplete fixes for command execution flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when avail
Bugzilla
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 nagios: snoopy: incomplete fixes for command execution flaws [fedora-all]
bugzilla·2014-07-21·CVSS 9.8
CVE-2014-5009 [CRITICAL] CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 nagios: snoopy: incomplete fixes for command execution flaws [fedora-all]
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 nagios: snoopy: incomplete fixes for command execution flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availabl
Bugzilla
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 sahana: snoopy: incomplete fixes for command execution flaws [fedora-all]
bugzilla·2014-07-21·CVSS 9.8
CVE-2014-5009 [CRITICAL] CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 sahana: snoopy: incomplete fixes for command execution flaws [fedora-all]
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 sahana: snoopy: incomplete fixes for command execution flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availabl
Bugzilla
CVE-2008-7313 CVE-2014-5008 CVE-2014-5009 snoopy: incomplete fixes for command execution flaws
bugzilla·2014-07-21·CVSS 10.0
CVE-2008-7313 [CRITICAL] CVE-2008-7313 CVE-2014-5008 CVE-2014-5009 snoopy: incomplete fixes for command execution flaws
CVE-2008-7313 CVE-2014-5008 CVE-2014-5009 snoopy: incomplete fixes for command execution flaws
CVE-2008-4796 describes a command execution flaw in the Snoopy library. A similar fix exists for headers:
http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.27
The header fix has been assigned CVE-2008-7313 (as an incomplete fix for CVE-2008-4796).
It was later reported that the CVE-2008-4796 fix was incomplete and command execution was still possible:
http://mstrokin.com/sec/feed2js-magpierss-0day-vulnerability-not-really-it-is-actually-cve-2005-3330-cve-2008-4796/
And fixed with the following:
http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.28
This has been assigned CVE-2014-5008 (as an incomplete fix for CVE-2008-
http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.27http://www.openwall.com/lists/oss-security/2014/07/09/11http://www.openwall.com/lists/oss-security/2014/07/16/10http://www.openwall.com/lists/oss-security/2014/07/18/2http://www.securityfocus.com/bid/68776https://bugzilla.redhat.com/show_bug.cgi?id=1121497https://exchange.xforce.ibmcloud.com/vulnerabilities/94737https://rhn.redhat.com/errata/RHSA-2017-0211.htmlhttps://rhn.redhat.com/errata/RHSA-2017-0212.htmlhttps://rhn.redhat.com/errata/RHSA-2017-0213.htmlhttps://rhn.redhat.com/errata/RHSA-2017-0214.htmlhttps://security.gentoo.org/glsa/201702-26https://www-01.ibm.com/support/docview.wss?uid=isg3T1024264http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.27http://www.openwall.com/lists/oss-security/2014/07/09/11http://www.openwall.com/lists/oss-security/2014/07/16/10http://www.openwall.com/lists/oss-security/2014/07/18/2http://www.securityfocus.com/bid/68776https://bugzilla.redhat.com/show_bug.cgi?id=1121497https://exchange.xforce.ibmcloud.com/vulnerabilities/94737https://rhn.redhat.com/errata/RHSA-2017-0211.htmlhttps://rhn.redhat.com/errata/RHSA-2017-0212.htmlhttps://rhn.redhat.com/errata/RHSA-2017-0213.htmlhttps://rhn.redhat.com/errata/RHSA-2017-0214.htmlhttps://security.gentoo.org/glsa/201702-26https://www-01.ibm.com/support/docview.wss?uid=isg3T1024264
2017-03-31
Published