Description: Nobuhiro Ban has reported a vulnerability in Nagios Plugins, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to a boundary error within the "redir()" function in check_http.c when processing HTTP "Location:" header information. This can be exploited to cause a buffer overflow by returning an overly long string in the "Location:" header to a vulnerable system.
Successful exploitation requires that a connection is made to a malicious web server.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.