---
title: "CVE-2014-2913\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2014-2913?format=md
keywords: index, follow
---

# CVE-2014-2913

Publication date 7 May 2014

Last updated 4 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin
Executor (NRPE) 2.15 and earlier allows remote attackers to execute
arbitrary commands via a newline character in the -a option to
libexec/check\_nrpe. NOTE: this issue is disputed by multiple parties. It
has been reported that the vendor allows newlines as "expected behavior."
Also, this issue can only occur when the administrator enables the
"dont\_blame\_nrpe" option in nrpe.conf despite the "HIGH security risk"
warning within the comments

[Read the notes from the security team](https://ubuntu.com/security/CVE-2014-2913?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| nagios-nrpe | 24.04 LTS noble | Not affected |
| 23.10 mantic | Ignored end of life, was needed |
| 23.04 lunar | Ignored end of life, was needed |
| 22.10 kinetic | Ignored end of life, was needed |
| 22.04 LTS jammy | Not affected |
| 21.10 impish | Ignored end of life |
| 21.04 hirsute | Ignored end of life |
| 20.10 groovy | Ignored end of life |
| 20.04 LTS focal | Not affected |
| 19.10 eoan | Ignored end of life |
| 19.04 disco | Ignored end of life |
| 18.10 cosmic | Ignored end of life |
| 18.04 LTS bionic | Not affected |
| 17.10 artful | Ignored end of life |
| 17.04 zesty | Ignored end of life |
| 16.10 yakkety | Ignored end of life |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Ignored end of life |
| 15.04 vivid | Ignored end of life |
| 14.10 utopic | Ignored end of life |
| 14.04 LTS trusty | Not in release |
| 13.10 saucy | Ignored end of life |
| 12.10 quantal | Ignored end of life |
| 12.04 LTS precise | Ignored end of life |
| 10.04 LTS lucid | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [seth-arnold](https://launchpad.net/~seth-arnold)

I marked this 'low' because arguments are discouraged for many
environments, access to NRPE can be restricted with firewalling or
other user access controls, and this might plausibly be a feature.

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2913)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2014-2913)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2014-2913)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2014-2913)

### Other references

* <http://seclists.org/fulldisclosure/2014/Apr/240>
* <http://seclists.org/fulldisclosure/2014/Apr/242>
* <https://www.cve.org/CVERecord?id=CVE-2014-2913>
