Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:0500-1

Опубликовано: 11 апр. 2020
Источник: suse-cvrf

Описание

Security update for nagios

This update for nagios to version 4.4.5 fixes the following issues:

  • CVE-2019-3698: Symbolic link following vulnerability in the cronjob allows local attackers to cause cause DoS or potentially escalate privileges. (boo#1156309)
  • CVE-2018-18245: Fixed XSS vulnerability in Alert Summary report (boo#1119832)
  • CVE-2018-13441, CVE-2018-13458, CVE-2018-13457: Fixed a few denial of service vulnerabilities caused by null pointer dereference (boo#1101293, boo#1101289, boo#1101290).

Список пакетов

openSUSE Leap 15.1
nagios-4.4.5-lp151.5.4.1
nagios-contrib-4.4.5-lp151.5.4.1
nagios-devel-4.4.5-lp151.5.4.1
nagios-theme-exfoliation-4.4.5-lp151.5.4.1
nagios-www-4.4.5-lp151.5.4.1
nagios-www-dch-4.4.5-lp151.5.4.1

Описание

qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.


Затронутые продукты
openSUSE Leap 15.1:nagios-4.4.5-lp151.5.4.1
openSUSE Leap 15.1:nagios-contrib-4.4.5-lp151.5.4.1
openSUSE Leap 15.1:nagios-devel-4.4.5-lp151.5.4.1
openSUSE Leap 15.1:nagios-theme-exfoliation-4.4.5-lp151.5.4.1

Ссылки

Описание

qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.


Затронутые продукты
openSUSE Leap 15.1:nagios-4.4.5-lp151.5.4.1
openSUSE Leap 15.1:nagios-contrib-4.4.5-lp151.5.4.1
openSUSE Leap 15.1:nagios-devel-4.4.5-lp151.5.4.1
openSUSE Leap 15.1:nagios-theme-exfoliation-4.4.5-lp151.5.4.1

Ссылки

Описание

qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.


Затронутые продукты
openSUSE Leap 15.1:nagios-4.4.5-lp151.5.4.1
openSUSE Leap 15.1:nagios-contrib-4.4.5-lp151.5.4.1
openSUSE Leap 15.1:nagios-devel-4.4.5-lp151.5.4.1
openSUSE Leap 15.1:nagios-theme-exfoliation-4.4.5-lp151.5.4.1

Ссылки

Описание

Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.


Затронутые продукты
openSUSE Leap 15.1:nagios-4.4.5-lp151.5.4.1
openSUSE Leap 15.1:nagios-contrib-4.4.5-lp151.5.4.1
openSUSE Leap 15.1:nagios-devel-4.4.5-lp151.5.4.1
openSUSE Leap 15.1:nagios-theme-exfoliation-4.4.5-lp151.5.4.1

Ссылки

Описание

UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue affects: SUSE Linux Enterprise Server 12 nagios version 3.5.1-5.27 and prior versions. SUSE Linux Enterprise Server 11 nagios version 3.0.6-1.25.36.3.1 and prior versions. openSUSE Factory nagios version 4.4.5-2.1 and prior versions.


Затронутые продукты
openSUSE Leap 15.1:nagios-4.4.5-lp151.5.4.1
openSUSE Leap 15.1:nagios-contrib-4.4.5-lp151.5.4.1
openSUSE Leap 15.1:nagios-devel-4.4.5-lp151.5.4.1
openSUSE Leap 15.1:nagios-theme-exfoliation-4.4.5-lp151.5.4.1

Ссылки