LWN.net Logo

nagios: arbitrary program execution

Package(s):nagios2, nagios3 CVE #(s):CVE-2009-2288
Created:July 3, 2009 Updated:August 11, 2009
Description: From the Ubuntu advisory: It was discovered that Nagios did not properly parse certain commands submitted using the WAP web interface. An authenticated user could exploit this flaw and execute arbitrary programs on the server.
Alerts:
SuSE SUSE-SR:2009:013 2009-08-11
Mandriva MDVSA-2009:187 2009-08-01
Gentoo 200907-15 2009-07-19
Debian DSA-1825-1 2009-07-03
Ubuntu USN-795-1 2009-07-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds