Login
Newsletter
Werbung

Sicherheit: Mangelnde Eingabeprüfung in nagios
Aktuelle Meldungen Distributionen
Name: Mangelnde Eingabeprüfung in nagios
ID: FEDORA-2021-b5e897a2e5
Distribution: Fedora
Plattformen: Fedora 32
Datum: So, 7. März 2021, 23:27
Referenzen: https://bugzilla.redhat.com/show_bug.cgi?id=1829114
https://bugzilla.redhat.com/show_bug.cgi?id=1932297
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13977
Applikationen: Nagios

Originalnachricht

-------------------------------------------------------------------------------
-
Fedora Update Notification
FEDORA-2021-b5e897a2e5
2021-03-07 13:52:38.179269
-------------------------------------------------------------------------------
-

Name : nagios
Product : Fedora 32
Version : 4.4.6
Release : 3.fc32
URL : https://www.nagios.org/projects/nagios-core/
Summary : Host/service/network monitoring program
Description :
Nagios is a program that will monitor hosts and services on your
network. It has the ability to send email or page alerts when a
problem arises and when a problem is resolved. Nagios is written
in C and is designed to run under Linux (and some other *NIX
variants) as a background process, intermittently running checks
on various services that you specify.

The actual service checks are performed by separate "plugin" programs
which return the status of the checks to Nagios. The plugins are
available at https://github.com/nagios-plugins/nagios-plugins

This package provides the core program, web interface, and documentation
files for Nagios. Development files are built as a separate package.

-------------------------------------------------------------------------------
-
Update Information:

Fix for CVE-2020-13977 BZ1849087 Require plugins needed for localhost
monitoring
(#1932297) Update to 4.4.6
-------------------------------------------------------------------------------
-
ChangeLog:

* Sat Feb 27 2021 Guido Aulisi <guido.aulisi@gmail.com> - 4.4.6-3
- Require plugins needed for localhost monitoring (#1932297)
* Tue Feb 23 2021 Guido Aulisi <guido.aulisi@gmail.com> - 4.4.6-2
- Fix systemd unit file permissions #1676334
* Sat Feb 20 2021 Guido Aulisi <guido.aulisi@gmail.com> - 4.4.6-1
- Update to 4.4.6
- Fix for CVE-2020-13977 #BZ1849087
- Some spec cleanup
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #1829114 - nagios-4.4.6 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1829114
[ 2 ] Bug #1849087 - CVE-2020-13977 nagios: URL injection
(post-authentication) vulnerability [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1849087
[ 3 ] Bug #1932297 - Nagios server rpm missing some nagios-plugins-*
dependency
https://bugzilla.redhat.com/show_bug.cgi?id=1932297
-------------------------------------------------------------------------------
-

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2021-b5e897a2e5' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung