Login
Newsletter
Werbung

Sicherheit: Preisgabe von Informationen in check-mk
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in check-mk
ID: FEDORA-2014-6810
Distribution: Fedora
Plattformen: Fedora 20
Datum: Di, 10. Juni 2014, 07:33
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0243
Applikationen: checkmk

Originalnachricht

Name        : check-mk
Product : Fedora 20
Version : 1.2.4p2
Release : 2.fc20
URL : http://mathias-kettner.de/check_mk
Summary : A new general purpose Nagios-plugin for retrieving data
Description :
check-mk is a general purpose Nagios-plugin for retrieving data. It adopts a
new approach for collecting data from operating systems and network components.
It obsoletes NRPE, check_by_ssh, NSClient, and check_snmp and it has many
benefits, the most important are a significant reduction of CPU usage on
the Nagios host and an automatic inventory of items to be checked on hosts.

-------------------------------------------------------------------------------
-
Update Information:

- Install the mk-job binary on /usr/bin.
- Make sure the proper permissions are given to /var/lib/check_mk_agent/job to
prevent any hard or symlink to be created by a normal user and pointing to any file on the filesystem exposing it on the check-mk-agent output being run as root.
-------------------------------------------------------------------------------
-
ChangeLog:

* Tue May 27 2014 Andrea Veri <averi@fedoraproject.org> - 1.2.4p2-2
- Install the mk-job binary on /usr/bin.
- Make sure the proper permissions are given to /var/lib/check_mk_agent/job
to prevent any hard or symlink to be created by a normal user and pointing
to any file on the filesystem exposing it on the check-mk-agent output being
run as root. Fixes BZ #1101669.
* Mon Apr 14 2014 Andrea Veri <averi@fedoraproject.org> - 1.2.4p2-1
- New upstream release.
* Wed Apr 2 2014 Andrea Veri <averi@fedoraproject.org> - 1.2.4p1-1
- New upstream release. Fixes the missing two CVEs that were still
left unfixed on 1.2.4:
- CVE-2014-2330
- CVE-2014-2331
* Tue Mar 25 2014 Andrea Veri <averi@fedoraproject.org> - 1.2.4-1
- New upstream release. Fixes the following CVEs:
- CVE-2014-2329
- CVE-2014-2332
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #1101669 - CVE-2014-0243 check-mk: arbitrary file disclosure flaw
as root
https://bugzilla.redhat.com/show_bug.cgi?id=1101669
-------------------------------------------------------------------------------
-

This update can be installed with the "yum" update program. Use
su -c 'yum update check-mk' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung