Описание
Security update for nagios
This update for nagios to version 4.4.5 fixes the following issues:
- CVE-2019-3698: Symbolic link following vulnerability in the cronjob allows local attackers to cause cause DoS or potentially escalate privileges. (boo#1156309)
- CVE-2018-18245: Fixed XSS vulnerability in Alert Summary report (boo#1119832)
- CVE-2018-13441, CVE-2018-13458, CVE-2018-13457: Fixed a few denial of service vulnerabilities caused by null pointer dereference (boo#1101293, boo#1101289, boo#1101290).
Список пакетов
openSUSE Leap 15.1
Ссылки
- E-Mail link for openSUSE-SU-2020:0500-1
- SUSE Security Ratings
- SUSE Bug 1028975
- SUSE Bug 1119832
- SUSE Bug 1156309
- SUSE CVE CVE-2018-13441 page
- SUSE CVE CVE-2018-13457 page
- SUSE CVE CVE-2018-13458 page
- SUSE CVE CVE-2018-18245 page
- SUSE CVE CVE-2019-3698 page
Описание
qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.
Затронутые продукты
Ссылки
- CVE-2018-13441
- SUSE Bug 1101293
Описание
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.
Затронутые продукты
Ссылки
- CVE-2018-13457
- SUSE Bug 1101290
Описание
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.
Затронутые продукты
Ссылки
- CVE-2018-13458
- SUSE Bug 1101289
Описание
Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.
Затронутые продукты
Ссылки
- CVE-2018-18245
- SUSE Bug 1119832
Описание
UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue affects: SUSE Linux Enterprise Server 12 nagios version 3.5.1-5.27 and prior versions. SUSE Linux Enterprise Server 11 nagios version 3.0.6-1.25.36.3.1 and prior versions. openSUSE Factory nagios version 4.4.5-2.1 and prior versions.
Затронутые продукты
Ссылки
- CVE-2019-3698
- SUSE Bug 1150550
- SUSE Bug 1156309