CVE-2014-5009
published 2017-03-31CVE-2014-5009: Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
PriorityP357critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.71%
90.8th percentile
Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libphp-snoopy | — | — |
| nagios | nagios | <= 4.2.3 | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5m9g-pc3f-6pgc: Snoopy allows remote attackers to execute arbitrary commands
ghsa_unreviewed·2022-05-17·CVSS 9.8
CVE-2014-5009 [CRITICAL] CWE-77 GHSA-5m9g-pc3f-6pgc: Snoopy allows remote attackers to execute arbitrary commands
Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
Red Hat
snoopy: incomplete fixes for command execution flaws
vendor_redhat·2014-07-03·CVSS 9.8
CVE-2014-5009 [CRITICAL] snoopy: incomplete fixes for command execution flaws
snoopy: incomplete fixes for command execution flaws
Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
Various command-execution flaws were found in the Snoopy library included with Nagios. These flaws allowed remote attackers to execute arbitrary commands by manipulating Nagios HTTP headers.
Package: nagios (Red Hat OpenStack Platform 3) - Will not fix
Package: nagios (Red Hat OpenStack Platform 4) - Will not fix
Package: nagios (Red Hat Storage 2.1) - Will not fix
Package: nagios (Red Hat Storage 3.0) - Will not fix
Debian
CVE-2014-5009: libphp-snoopy - Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulner...
vendor_debian·2014·CVSS 9.8
CVE-2014-5009 [CRITICAL] CVE-2014-5009: libphp-snoopy - Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulner...
Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
Scope: local
bookworm: resolved
bullseye: resolved
sid: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 wordpress-mu: snoopy: incomplete fixes for command execution flaws [epel-5]
bugzilla·2014-07-21·CVSS 9.8
CVE-2014-5009 [CRITICAL] CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 wordpress-mu: snoopy: incomplete fixes for command execution flaws [epel-5]
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 wordpress-mu: snoopy: incomplete fixes for command execution flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when a
Bugzilla
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 sahana: snoopy: incomplete fixes for command execution flaws [epel-5]
bugzilla·2014-07-21·CVSS 9.8
CVE-2014-5009 [CRITICAL] CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 sahana: snoopy: incomplete fixes for command execution flaws [epel-5]
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 sahana: snoopy: incomplete fixes for command execution flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availab
Bugzilla
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 nagios: snoopy: incomplete fixes for command execution flaws [epel-all]
bugzilla·2014-07-21·CVSS 9.8
CVE-2014-5009 [CRITICAL] CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 nagios: snoopy: incomplete fixes for command execution flaws [epel-all]
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 nagios: snoopy: incomplete fixes for command execution flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when avail
Bugzilla
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 nagios: snoopy: incomplete fixes for command execution flaws [fedora-all]
bugzilla·2014-07-21·CVSS 9.8
CVE-2014-5009 [CRITICAL] CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 nagios: snoopy: incomplete fixes for command execution flaws [fedora-all]
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 nagios: snoopy: incomplete fixes for command execution flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availabl
Bugzilla
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 sahana: snoopy: incomplete fixes for command execution flaws [fedora-all]
bugzilla·2014-07-21·CVSS 9.8
CVE-2014-5009 [CRITICAL] CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 sahana: snoopy: incomplete fixes for command execution flaws [fedora-all]
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 sahana: snoopy: incomplete fixes for command execution flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availabl
Bugzilla
CVE-2008-7313 CVE-2014-5008 CVE-2014-5009 snoopy: incomplete fixes for command execution flaws
bugzilla·2014-07-21·CVSS 10.0
CVE-2008-7313 [CRITICAL] CVE-2008-7313 CVE-2014-5008 CVE-2014-5009 snoopy: incomplete fixes for command execution flaws
CVE-2008-7313 CVE-2014-5008 CVE-2014-5009 snoopy: incomplete fixes for command execution flaws
CVE-2008-4796 describes a command execution flaw in the Snoopy library. A similar fix exists for headers:
http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.27
The header fix has been assigned CVE-2008-7313 (as an incomplete fix for CVE-2008-4796).
It was later reported that the CVE-2008-4796 fix was incomplete and command execution was still possible:
http://mstrokin.com/sec/feed2js-magpierss-0day-vulnerability-not-really-it-is-actually-cve-2005-3330-cve-2008-4796/
And fixed with the following:
http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.28
This has been assigned CVE-2014-5008 (as an incomplete fix for CVE-2008-
http://rhn.redhat.com/errata/RHSA-2017-0211.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0212.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0213.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0214.htmlhttp://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?r1=1.28&r2=1.29http://www.openwall.com/lists/oss-security/2014/07/09/11http://www.openwall.com/lists/oss-security/2014/07/16/10http://www.openwall.com/lists/oss-security/2014/07/18/2http://www.securityfocus.com/bid/68783https://bugzilla.redhat.com/show_bug.cgi?id=1121497https://exchange.xforce.ibmcloud.com/vulnerabilities/94738https://github.com/cogdog/feed2js/pull/12#issuecomment-48283706https://www-01.ibm.com/support/docview.wss?uid=isg3T1024264http://rhn.redhat.com/errata/RHSA-2017-0211.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0212.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0213.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0214.htmlhttp://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?r1=1.28&r2=1.29http://www.openwall.com/lists/oss-security/2014/07/09/11http://www.openwall.com/lists/oss-security/2014/07/16/10http://www.openwall.com/lists/oss-security/2014/07/18/2http://www.securityfocus.com/bid/68783https://bugzilla.redhat.com/show_bug.cgi?id=1121497https://exchange.xforce.ibmcloud.com/vulnerabilities/94738https://github.com/cogdog/feed2js/pull/12#issuecomment-48283706https://www-01.ibm.com/support/docview.wss?uid=isg3T1024264
2017-03-31
Published