Buffer overflow in the redir function in check_http.c in Nagios Plugins before 1.4.10, when running with the -f (follow) option, allows remote web servers to execute arbitrary code via Location header responses (redirects) with a large number of leading “L” characters.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5198
Reference (s):
- BID:25952
- URL: http://www.securityfocus.com/bid/25952
- http://bugs.gentoo.org/show_bug.cgi?id=194178
- http://sourceforge.net/forum/forum.php?forum_id=740172
- http://sourceforge.net/tracker/index.php?func=detail&aid=1687867&group_id=29880&atid=397597