drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in check-mk
Name: |
Mehrere Probleme in check-mk |
|
ID: |
FEDORA-2014-10972 |
|
Distribution: |
Fedora |
|
Plattformen: |
Fedora 20 |
|
Datum: |
So, 28. September 2014, 00:25 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5338
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5339
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5340 |
|
Applikationen: |
checkmk |
|
Originalnachricht |
Name : check-mk Product : Fedora 20 Version : 1.2.4p5 Release : 1.fc20 URL : http://mathias-kettner.de/check_mk Summary : A new general purpose Nagios-plugin for retrieving data Description : check-mk is a general purpose Nagios-plugin for retrieving data. It adopts a new approach for collecting data from operating systems and network components. It obsoletes NRPE, check_by_ssh, NSClient, and check_snmp and it has many benefits, the most important are a significant reduction of CPU usage on the Nagios host and an automatic inventory of items to be checked on hosts.
------------------------------------------------------------------------------- - Update Information:
New upstream release providing many security fixes. ------------------------------------------------------------------------------- - ChangeLog:
* Wed Sep 17 2014 Andrea Veri <averi@fedoraproject.org> - 1.2.4p5-1 - New upstream release. Fixes CVEs: - CVE-2014-5338 - CVE-2014-5339 - CVE-2014-5340 (BZ: #1132337, #1132339, #1132341) - Stop shipping the j4p_performance plugin as it's deprecated. (BZ: #1133068) - Turn Wato_Legacy_Eval as True as we want to prevent breakages between machines running different Python and/or check-mk releases. This is necessary after the 'ast' move from 'pickle' (that was generating a insecure API call), however the 'ast' module is still not available for RHEL / CentOS 5 machines. The patch is there to avoid miscommunications between different distribution releases. More information is available at: http://mathias-kettner.com/check_mk_werks.php?werk_id=984. * Sat Aug 16 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.4p2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild * Sat Jun 7 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.4p2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild * Tue May 27 2014 Andrea Veri <averi@fedoraproject.org> - 1.2.4p2-2 - Install the mk-job binary on /usr/bin. - Make sure the proper permissions are given to /var/lib/check_mk_agent/job to prevent any hard or symlink to be created by a normal user and pointing to any file on the filesystem exposing it on the check-mk-agent output being run as root. Fixes BZ #1101669. * Mon Apr 14 2014 Andrea Veri <averi@fedoraproject.org> - 1.2.4p2-1 - New upstream release. * Wed Apr 2 2014 Andrea Veri <averi@fedoraproject.org> - 1.2.4p1-1 - New upstream release. Fixes the missing two CVEs that were still left unfixed on 1.2.4: - CVE-2014-2330 - CVE-2014-2331 * Tue Mar 25 2014 Andrea Veri <averi@fedoraproject.org> - 1.2.4-1 - New upstream release. Fixes the following CVEs: - CVE-2014-2329 - CVE-2014-2332 ------------------------------------------------------------------------------- - References:
[ 1 ] Bug #1132337 - CVE-2014-5338 CVE-2014-5339 CVE-2014-5340 check-mk: multiple flaws fixed in versions 1.2.4p4 and 1.2.5i4 https://bugzilla.redhat.com/show_bug.cgi?id=1132337 ------------------------------------------------------------------------------- -
This update can be installed with the "yum" update program. Use su -c 'yum update check-mk' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys ------------------------------------------------------------------------------- - _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-announce
|
|
|
|