Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in check-mk
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in check-mk
ID: FEDORA-2014-5139
Distribution: Fedora
Plattformen: Fedora 19
Datum: Do, 24. April 2014, 18:43
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2329
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2330
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2331
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2332
Applikationen: checkmk

Originalnachricht

Name        : check-mk
Product : Fedora 19
Version : 1.2.4p2
Release : 1.fc19
URL : http://mathias-kettner.de/check_mk
Summary : A new general purpose Nagios-plugin for retrieving data
Description :
check-mk is a general purpose Nagios-plugin for retrieving data. It adopts a
new approach for collecting data from operating systems and network components.
It obsoletes NRPE, check_by_ssh, NSClient, and check_snmp and it has many
benefits, the most important are a significant reduction of CPU usage on
the Nagios host and an automatic inventory of items to be checked on hosts.

-------------------------------------------------------------------------------
-
Update Information:

New upstream release.
Fixes CVEs:

- CVE-2014-2329
- CVE-2014-2330
- CVE-2014-2331
- CVE-2014-2332
Fixes CVEs:

- CVE-2014-2329
- CVE-2014-2330
- CVE-2014-2331
- CVE-2014-2332
Fixes CVEs:

- CVE-2014-2329
- CVE-2014-2330
- CVE-2014-2331
- CVE-2014-2332
Fixes CVEs:

- CVE-2014-2329
- CVE-2014-2330
- CVE-2014-2331
- CVE-2014-2332
-------------------------------------------------------------------------------
-
ChangeLog:

* Mon Apr 14 2014 Andrea Veri <averi@fedoraproject.org> - 1.2.4p2-1
- New upstream release.
* Wed Apr 2 2014 Andrea Veri <averi@fedoraproject.org> - 1.2.4p1-1
- New upstream release. Fixes the missing two CVEs that were still
left unfixed on 1.2.4:
- CVE-2014-2330
- CVE-2014-2331
* Tue Mar 25 2014 Andrea Veri <averi@fedoraproject.org> - 1.2.4-1
- New upstream release. Fixes the following CVEs:
- CVE-2014-2329
- CVE-2014-2332
* Wed Oct 2 2013 Andrea Veri <averi@fedoraproject.org> - 1.2.2p2-2
- Make sure an /etc/check_mk/conf.d/wato directory is created for WATO
to work properly. (BZ: #987863)
- Improve the packages description.
* Sat Aug 31 2013 Andrea Veri <averi@fedoraproject.org> - 1.2.2p2-1
- New upstream release.
* Thu Aug 29 2013 Andrea Veri <averi@fedoraproject.org> - 1.2.2-6
- Make sure the waitmax binary gets built. Also thanks to John Reddy
for his initial work on this. (BZ: #982769)
- Add an if statement for RHEL and make sure auto provides are not set
automatically. (BZ #985285)
- Requires set to mod_python on RHEL, no mod_wsgi migration yet on EPEL. (BZ:
#987852)
- Fix the perl command that was doing the needed substitution on the
/usr/bin/check_mk_agent's configuration directories. Thanks Brainslug for
the
report. (BZ: #989793)
- In addition to a customized 'defaults' file, add a defaults.py
accordingly. (BZ: #987859)
* Fri Aug 2 2013 Petr Pisar <ppisar@redhat.com> - 1.2.2-5
- Do not provide from a documentation
* Sun Apr 28 2013 Andrea Veri <averi@fedoraproject.org> 1.2.2-5.fc19
- Make sure the Nagios library path on the check_mk_templates.cfg file
is correct on both x86_64 and i686 systems.
* Sat Apr 27 2013 Andrea Veri <averi@fedoraproject.org> 1.2.2-4.fc19
- Change check-mk-agent's binary name to check_mk_agent to match
xinetd's file. (BZ: #956489)
- Remove other operating systems agents, we definitely don't need them on
this package.
- Make sure that check_mk_templates gets shipped into /etc/nagios/conf.d. (BZ:
#956492)
- Don't ship the auto-generated defaults file, but provide it with our
customizations. This actually
fixes BZ: #956496 since we modify the checkresults path to be the same as the
one provided
by Nagios itself, thus no need to create an additional directory.
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #1080303 - CVE-2014-2329 CVE-2014-2330 CVE-2014-2331 CVE-2014-2332
check-mk: multiple flaws fixed in versions 1.2.2p3 and 1.2.3i5
https://bugzilla.redhat.com/show_bug.cgi?id=1080303
-------------------------------------------------------------------------------
-

This update can be installed with the "yum" update program. Use
su -c 'yum update check-mk' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung