LWN.net Logo

nagstamon: information disclosure

Package(s):nagstamon CVE #(s):CVE-2013-4114
Created:July 16, 2013 Updated:September 3, 2013
Description: From the Red Hat bugzilla:

An user details information exposure flaw was found in the way Nagstamon, Nagios status monitor for desktop, performed automated requests to get information about available updates. Remote attacker could use this flaw to obtain user credentials for server monitored by the desktop status monitor due to their improper (base64 encoding based) encoding in the HTTP request, when the HTTP Basic authentication scheme was used.

Alerts:
Fedora FEDORA-2013-12526 2013-07-16
Fedora FEDORA-2013-12541 2013-07-16
openSUSE openSUSE-SU-2013:1235-1 2013-07-23
Mageia MGASA-2013-0262 2013-08-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds