cbcvebase.
CVE-2014-5008
published 2017-03-31

CVE-2014-5008: Snoopy allows remote attackers to execute arbitrary commands.

PriorityP265critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.13%
89.7th percentile
Snoopy allows remote attackers to execute arbitrary commands.

Affected

6 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlibphp-snoopy< libphp-snoopy 2.0.0-1 (bookworm)libphp-snoopy 2.0.0-1 (bookworm)
debianlibphp-snoopy
nagiosnagios<= 4.2.3
redhatopenstack
redhatopenstack

Detection & IOCsextracted from sources · hover to see the quote

  • Attackers exploit CVE-2014-5008 by manipulating Nagios HTTP headers to achieve command execution via the Snoopy library bundled with Nagios.
  • The vulnerable code path is in Snoopy.class.php; review revision history at the upstream CVS for the patched version (rev1.29) to identify the dangerous code patterns.
  • ·Red Hat explicitly marked nagios packages in OpenStack Platform 3, OpenStack Platform 4, Red Hat Storage 2.1, and Red Hat Storage 3.0 as 'Will not fix', meaning these deployments remain permanently vulnerable unless mitigated externally.
  • ·CVE-2014-5008 had an incomplete fix; CVE-2014-5009 (and CVE-2008-7313) represent additional bypass variants of the same command-execution flaw in Snoopy. Detection and patching must address all three CVEs together.
  • ·The Snoopy library was embedded in multiple packages (nagios, sahana, wordpress-mu); all bundled copies must be updated independently to Snoopy 2.0.0-1 or later.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.