Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.61929
Category:Fedora Local Security Checks
Title:Fedora Core 10 FEDORA-2008-10323 (nagios)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to nagios
announced via advisory FEDORA-2008-10323.

Update Information:

Upstream has released a new version:
* Security fix for Cross Site Request Forgery (CSRF)
bug reported by Tim Starling.
* Sample audio files for CGIs removed from distribution
* Fix for mutliline config file continuation bug
* Minor fix to RPM spec file
* Fix for AIX compiler warnings
* Minor sample config file fix
* Added documentation on CGI security issues

ChangeLog:

* Mon Nov 24 2008 Mike McGrath 3.0.5-1
- Upstream released a new version

References:

[ 1 ] Bug #470840 - CVE-2008-5027 nagios: authorization bypass via custom form or browser addon
https://bugzilla.redhat.com/show_bug.cgi?id=470840

Solution: Apply the appropriate updates.

This update can be installed with the yum update program. Use
su -c 'yum update nagios' at the command line.
For more information, refer to Managing Software with yum,
available at http://docs.fedoraproject.org/yum/.

http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-10323

Risk factor : High

CVSS Score:
6.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-5027
BugTraq ID: 32156
http://www.securityfocus.com/bid/32156
http://security.gentoo.org/glsa/glsa-200907-15.xml
HPdes Security Advisory: HPSBMA02419
http://marc.info/?l=bugtraq&m=124156641928637&w=2
HPdes Security Advisory: SSRT090060
http://www.nagios.org/development/history/nagios-3x.php
http://sourceforge.net/mailarchive/forum.php?thread_name=4914396D.5010009%40op5.se&forum_name=nagios-devel
http://www.openwall.com/lists/oss-security/2008/11/06/2
http://www.securitytracker.com/id?1022165
http://secunia.com/advisories/33320
http://secunia.com/advisories/35002
http://www.ubuntu.com/usn/USN-698-1
https://www.ubuntu.com/usn/USN-698-3/
http://www.vupen.com/english/advisories/2008/3029
http://www.vupen.com/english/advisories/2008/3364
http://www.vupen.com/english/advisories/2009/1256
CopyrightCopyright (c) 2008 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.