Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9565

Опубликовано: 13 дек. 2016
Источник: redhat
CVSS3: 8.1
CVSS2: 6.8
EPSS Средний

Описание

MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.

It was found that an attacker who could control the content of an RSS feed could execute code remotely using the Nagios web interface. This flaw could be used to gain access to the remote system and in some scenarios control over the system.

Меры по смягчению последствий

#!/bin/bash mv /usr/share/nagios/html/includes/rss /usr/share/nagios/html/includes/rss.disarmed mv /usr/share/nagios/html/rss-corefeed.php /usr/share/nagios/html/rss-corefeed.php.disarmed mv /usr/share/nagios/html/rss-newsfeed.php /usr/share/nagios/html/rss-newsfeed.php.disarmed This should disable rss from nagios installation and stop affected php code from being executed. Only downside to this would be news widget wont fetch any data from nagios.org rss feeds.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Mobile Application Platform 4nagiosWill not fix
Red Hat OpenStack Platform 10 (Newton)nagiosNot affected
Red Hat OpenStack Platform 8 (Liberty)nagiosNot affected
Red Hat OpenStack Platform 9 (Mitaka)nagiosNot affected
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6nagiosFixedRHSA-2017:021231.01.2017
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7nagiosFixedRHSA-2017:021131.01.2017
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7nagiosFixedRHSA-2017:021331.01.2017
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7nagiosFixedRHSA-2017:021431.01.2017
Red Hat Gluster Storage 3.1 for RHEL 6nagiosFixedRHSA-2017:025907.02.2017
Red Hat Gluster Storage 3.1 for RHEL 7nagiosFixedRHSA-2017:025807.02.2017

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=1405363nagios: Command injection via curl in MagpieRSS

EPSS

Процентиль: 95%
0.19945
Средний

8.1 High

CVSS3

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 9 лет назад

MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.

CVSS3: 9.8
nvd
около 9 лет назад

MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.

CVSS3: 9.8
debian
около 9 лет назад

MagpieRSS, as used in the front-end component in Nagios Core before 4. ...

CVSS3: 9.8
github
больше 3 лет назад

MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.

EPSS

Процентиль: 95%
0.19945
Средний

8.1 High

CVSS3

6.8 Medium

CVSS2