Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Microsoft Office Clone Updates Interface, Improves File Support
· Windows Firewall Control 4.0.0.0 released
· 10 amazing Linux desktop environments you've probably never seen
· Microsoft Office security flaw hits thousands in latest hacker attack
· Kubuntu 13.04 Raring Ringtail Review
· Windows Mobile 7 concept video shows why Microsoft dumped the platform
· Building a Thin Mini-ITX PC and more
· Microsoft wants consumers to control the camera by voice, according to filed patent
· Dell replays Windows 8 blame card as PC sales slide
· m23 rock 13.1 released

Upcoming News
· Jawbone UP Wristband
· Seagate Desktop HDD.15 4TB Hard Drive Review @ Hardware Canucks
· Steelseries WoW MMO Gaming Mouse Legendary Edition Review
· Luxa2 P1 7000mAh High Capacity Battery & Charger Review @ OCC
· GUNNAR Intercept Gaming Eyewear Video Review with Kaeyi Dream @ HardwareHeaven.com
· [slackware-security] kernel (SSA:2013-140-01)
· [CentOS-announce] CEBA-2013:0835 CentOS 6 selinux-policy Update
· Ubuntu Weekly Newsletter Issue 317
· [RHSA-2013:0841-01] Important: kernel security update
· [RHSA-2013:0829-01] Important: kernel-rt security and bug fix update

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6368 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 651 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4510 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 715 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1105 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » December 2008 » USN-698-2: Nagios3 vulnerabilities

USN-698-2: Nagios3 vulnerabilities

Posted by Bob on: 12/22/2008 03:45 PM [ Print | 0 comment(s) ]

A new Nagios3 vulnerabilities update is available for Ubuntu Linux. Here the announcement:




Ubuntu Security Notice USN-698-2 December 22, 2008
nagios3 vulnerabilities
CVE-2008-5027, CVE-2008-5028
==========================
==========================
=========

A security issue affects the following Ubuntu releases:

Ubuntu 8.10

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 8.10:
nagios3 3.0.2-1ubuntu1.1

After a standard system upgrade you need to restart Nagios to effect
the necessary changes.

Details follow:

It was discovered that Nagios was vulnerable to a Cross-site request forger=
y
(CSRF) vulnerability. If an authenticated nagios user were tricked into
clicking a link on a specially crafted web page, an attacker could trigger
commands to be processed by Nagios and execute arbitrary programs. This
update alters Nagios behaviour by disabling submission of CMD_CHANGE comman=
ds.
(CVE-2008-5028)

It was discovered that Nagios did not properly parse commands submitted usi=
ng
the web interface. An authenticated user could use a custom form or a brows=
er
addon to bypass security restrictions and submit unauthorized commands.
(CVE-2008-5027)


Updated packages for Ubuntu 8.10:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3_3.0.2-1ub=
untu1.1.diff.gz
Size/MD5: 38086 84020bf2660e52ef176a2274971e4c1b
http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3_3.0.2-1ub=
untu1.1.dsc
Size/MD5: 1644 868828fdabd748689e35083aa052a483
http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3_3.0.2.ori=
g.tar.gz
Size/MD5: 2759331 008d71aac08660bc007f7130ea82ab80

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3-common_3.=
0.2-1ubuntu1.1_all.deb
Size/MD5: 72216 1cccb3e8640dbd2612caf7841ae1756b
http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3-doc_3.0.2=
-1ubuntu1.1_all.deb
Size/MD5: 2063224 9769666c13c1d886228f66ff40dc729a

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3-dbg_3.0.2=
-1ubuntu1.1_amd64.deb
Size/MD5: 2660164 381e889f994b102f6e65acc67f032f7a
http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3_3.0.2-1ub=
untu1.1_amd64.deb
Size/MD5: 1538712 8ce98eee89e13bc544180c73c9d24ba0

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3-dbg_3.0.2=
-1ubuntu1.1_i386.deb
Size/MD5: 2429130 87889b6dc28b86c4aae3d0acdd9950e9
http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3_3.0.2-1ub=
untu1.1_i386.deb
Size/MD5: 1387398 ec353697aced7539893ef9409d850120

lpia architecture (Low Power Intel Architecture):

http://ports.ubuntu.com/pool/main/n/nagios3/nagios3-dbg_3.0.2-1ubuntu1.=
1_lpia.deb
Size/MD5: 2479724 433504296b1650a7d393ab28d9b264b7
http://ports.ubuntu.com/pool/main/n/nagios3/nagios3_3.0.2-1ubuntu1.1_lp=
ia.deb
Size/MD5: 1376480 be232a1c16b5daff63b586f2cd66b9eb

powerpc architecture (Apple Macintosh G3/G4/G5):

http://ports.ubuntu.com/pool/main/n/nagios3/nagios3-dbg_3.0.2-1ubuntu1.=
1_powerpc.deb
Size/MD5: 2630802 167b533ea10d8962df5bc5904133c067
http://ports.ubuntu.com/pool/main/n/nagios3/nagios3_3.0.2-1ubuntu1.1_po=
werpc.deb
Size/MD5: 1525154 0679044c20e6a53c9311f2670834035b

sparc architecture (Sun SPARC/UltraSPARC):

http://ports.ubuntu.com/pool/main/n/nagios3/nagios3-dbg_3.0.2-1ubuntu1.=
1_sparc.deb
Size/MD5: 2327204 f40329c8a8216799a365d185bcc2a646
http://ports.ubuntu.com/pool/main/n/nagios3/nagios3_3.0.2-1ubuntu1.1_sp=
arc.deb
Size/MD5: 1379752 04408878bff9de5f485c7da2c6ffde4d



--=-mYyGRrkIRz8XgQEsC6l+
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEABECAAYFAklPpfgACgkQLMAs/0C4zNpDNQCghNyH1tzwJKxy8CXSiIIzUXFQ
NHYAoIRdJ1EZWi6MB04DPzzobx3KG9TE
=gM9K
-----END PGP SIGNATURE-----


Bookmark and Share

« USN-699-1: Blender vulnerabilities · Seasonic M12D 850 Watt PSU Review »

Linux Compatible » News » December 2008 » USN-698-2: Nagios3 vulnerabilities
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition