Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:1417-1

Опубликовано: 24 апр. 2024
Источник: suse-cvrf

Описание

Security update for nrpe

This update for nrpe fixes the following issues:

CVE-2014-2913: Fixed remote command execution when command arguments are enabled (bsc#1118590,bsc#874743)

Список пакетов

SUSE Linux Enterprise Server 12 SP5
monitoring-plugins-nrpe-2.15-6.6.1
nrpe-2.15-6.6.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
monitoring-plugins-nrpe-2.15-6.6.1
nrpe-2.15-6.6.1

Описание

** DISPUTED ** Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary commands via a newline character in the -a option to libexec/check_nrpe. NOTE: this issue is disputed by multiple parties. It has been reported that the vendor allows newlines as "expected behavior." Also, this issue can only occur when the administrator enables the "dont_blame_nrpe" option in nrpe.conf despite the "HIGH security risk" warning within the comments.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5:monitoring-plugins-nrpe-2.15-6.6.1
SUSE Linux Enterprise Server 12 SP5:nrpe-2.15-6.6.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5:monitoring-plugins-nrpe-2.15-6.6.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5:nrpe-2.15-6.6.1

Ссылки