Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Daily Reviews Summary 05/25/12
· CompatDB Updates 05/25/12
· Rumor: Microsoft Office coming to iPad, Android in November
· Microsoft clarifies Ballmer's claims of massive Windows 8 adoption
· DSA 2480-1: request-tracker3.8 security update
· CentOS 6 NTP Server
· Daily Reviews Summary 05/24/12
· Bayan Audio - Bayan 7 iPod Speaker Dock Review
· Installing Nginx With PHP5 (And PHP-FPM) And MySQL Support (LEMP) On Ubuntu 12.04 LTS
· Ubuntu 12.04 + Nvidia - Heavy CPU usage

Upcoming News
· Blues Brothers 2000 (1998) Blu-ray Movie Review
· Thermaltake ToughPower Grand 850W Power Supply Review @ Rbmods
· Cooler Master Silent Pro Gold 1200-watt Power Supply Review
· Wine release 1.5.5
· OC3D: BitFenix Prodigy Review
· [Tech ARP] The New x264 HD Benchmark 5.0 Is Here!
· re: Diablo III Reviewed: Blizzard's Brilliant, Blundering Wreck
· Corsair Vengeance C70 Case Review @ Hardware Secrets
· Diablo III Reviewed: Blizzard's Brilliant, Blundering Wreck
· Samsung Green DDR3 8GB 1600mhz 30nm Memory review

Linux Compatibility
· Canon Canoscan N650U
· TB-5300 Slimline Design Tablet
· HANDYCAM DCR-HC17E
· Linksys Wireless-G WPC54G PC-Card
· XPS L502X
· Slim Portable DVD Writer GP10
· AverTV Volar Green HD
· Dell Latitude E6420
· Canon CanoScan FB 636U
· Logitech QuickCam Pro 4000

New Forum Topics
· present.However after the Kou
by: Thomasxpp
on: 2012-05-26 02:12
0 replies, 0 views

· business, hand over to Ji
by: Thomasxpp
on: 2012-05-26 02:09
0 replies, 0 views

· a war in the outside and quells
by: Thomasxpp
on: 2012-05-26 02:06
0 replies, 0 views

· This among them the
by: Thomasxpp
on: 2012-05-26 02:02
0 replies, 0 views

· USB Not detected on any PC
by: AntNik45
on: 2012-05-09 18:37
0 replies, 0 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » December 2008 » USN-698-2: Nagios3 vulnerabilities

USN-698-2: Nagios3 vulnerabilities

Posted by Bob on: 12/22/2008 03:45 PM [ Print | 0 comment(s) ]

A new Nagios3 vulnerabilities update is available for Ubuntu Linux. Here the announcement:




Ubuntu Security Notice USN-698-2 December 22, 2008
nagios3 vulnerabilities
CVE-2008-5027, CVE-2008-5028
==========================
==========================
=========

A security issue affects the following Ubuntu releases:

Ubuntu 8.10

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 8.10:
nagios3 3.0.2-1ubuntu1.1

After a standard system upgrade you need to restart Nagios to effect
the necessary changes.

Details follow:

It was discovered that Nagios was vulnerable to a Cross-site request forger=
y
(CSRF) vulnerability. If an authenticated nagios user were tricked into
clicking a link on a specially crafted web page, an attacker could trigger
commands to be processed by Nagios and execute arbitrary programs. This
update alters Nagios behaviour by disabling submission of CMD_CHANGE comman=
ds.
(CVE-2008-5028)

It was discovered that Nagios did not properly parse commands submitted usi=
ng
the web interface. An authenticated user could use a custom form or a brows=
er
addon to bypass security restrictions and submit unauthorized commands.
(CVE-2008-5027)


Updated packages for Ubuntu 8.10:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3_3.0.2-1ub=
untu1.1.diff.gz
Size/MD5: 38086 84020bf2660e52ef176a2274971e4c1b
http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3_3.0.2-1ub=
untu1.1.dsc
Size/MD5: 1644 868828fdabd748689e35083aa052a483
http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3_3.0.2.ori=
g.tar.gz
Size/MD5: 2759331 008d71aac08660bc007f7130ea82ab80

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3-common_3.=
0.2-1ubuntu1.1_all.deb
Size/MD5: 72216 1cccb3e8640dbd2612caf7841ae1756b
http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3-doc_3.0.2=
-1ubuntu1.1_all.deb
Size/MD5: 2063224 9769666c13c1d886228f66ff40dc729a

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3-dbg_3.0.2=
-1ubuntu1.1_amd64.deb
Size/MD5: 2660164 381e889f994b102f6e65acc67f032f7a
http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3_3.0.2-1ub=
untu1.1_amd64.deb
Size/MD5: 1538712 8ce98eee89e13bc544180c73c9d24ba0

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3-dbg_3.0.2=
-1ubuntu1.1_i386.deb
Size/MD5: 2429130 87889b6dc28b86c4aae3d0acdd9950e9
http://security.ubuntu.com/ubuntu/pool/main/n/nagios3/nagios3_3.0.2-1ub=
untu1.1_i386.deb
Size/MD5: 1387398 ec353697aced7539893ef9409d850120

lpia architecture (Low Power Intel Architecture):

http://ports.ubuntu.com/pool/main/n/nagios3/nagios3-dbg_3.0.2-1ubuntu1.=
1_lpia.deb
Size/MD5: 2479724 433504296b1650a7d393ab28d9b264b7
http://ports.ubuntu.com/pool/main/n/nagios3/nagios3_3.0.2-1ubuntu1.1_lp=
ia.deb
Size/MD5: 1376480 be232a1c16b5daff63b586f2cd66b9eb

powerpc architecture (Apple Macintosh G3/G4/G5):

http://ports.ubuntu.com/pool/main/n/nagios3/nagios3-dbg_3.0.2-1ubuntu1.=
1_powerpc.deb
Size/MD5: 2630802 167b533ea10d8962df5bc5904133c067
http://ports.ubuntu.com/pool/main/n/nagios3/nagios3_3.0.2-1ubuntu1.1_po=
werpc.deb
Size/MD5: 1525154 0679044c20e6a53c9311f2670834035b

sparc architecture (Sun SPARC/UltraSPARC):

http://ports.ubuntu.com/pool/main/n/nagios3/nagios3-dbg_3.0.2-1ubuntu1.=
1_sparc.deb
Size/MD5: 2327204 f40329c8a8216799a365d185bcc2a646
http://ports.ubuntu.com/pool/main/n/nagios3/nagios3_3.0.2-1ubuntu1.1_sp=
arc.deb
Size/MD5: 1379752 04408878bff9de5f485c7da2c6ffde4d



--=-mYyGRrkIRz8XgQEsC6l+
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEABECAAYFAklPpfgACgkQLMAs/0C4zNpDNQCghNyH1tzwJKxy8CXSiIIzUXFQ
NHYAoIRdJ1EZWi6MB04DPzzobx3KG9TE
=gM9K
-----END PGP SIGNATURE-----


Bookmark and Share

« USN-699-1: Blender vulnerabilities · Seasonic M12D 850 Watt PSU Review »

Linux Compatible » News » December 2008 » USN-698-2: Nagios3 vulnerabilities
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2011 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition