Fedora alert FEDORA-2014-6810 (check-mk)
From: | updates@fedoraproject.org | |
To: | package-announce@lists.fedoraproject.org | |
Subject: | [SECURITY] Fedora 20 Update: check-mk-1.2.4p2-2.fc20 | |
Date: | Tue, 10 Jun 2014 03:09:47 +0000 | |
Message-ID: | <20140610030947.53F0A22028@bastion01.phx2.fedoraproject.org> |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2014-6810 2014-05-28 23:11:46 -------------------------------------------------------------------------------- Name : check-mk Product : Fedora 20 Version : 1.2.4p2 Release : 2.fc20 URL : http://mathias-kettner.de/check_mk Summary : A new general purpose Nagios-plugin for retrieving data Description : check-mk is a general purpose Nagios-plugin for retrieving data. It adopts a new approach for collecting data from operating systems and network components. It obsoletes NRPE, check_by_ssh, NSClient, and check_snmp and it has many benefits, the most important are a significant reduction of CPU usage on the Nagios host and an automatic inventory of items to be checked on hosts. -------------------------------------------------------------------------------- Update Information: - Install the mk-job binary on /usr/bin. - Make sure the proper permissions are given to /var/lib/check_mk_agent/job to prevent any hard or symlink to be created by a normal user and pointing to any file on the filesystem exposing it on the check-mk-agent output being run as root. -------------------------------------------------------------------------------- ChangeLog: * Tue May 27 2014 Andrea Veri <averi@fedoraproject.org> - 1.2.4p2-2 - Install the mk-job binary on /usr/bin. - Make sure the proper permissions are given to /var/lib/check_mk_agent/job to prevent any hard or symlink to be created by a normal user and pointing to any file on the filesystem exposing it on the check-mk-agent output being run as root. Fixes BZ #1101669. * Mon Apr 14 2014 Andrea Veri <averi@fedoraproject.org> - 1.2.4p2-1 - New upstream release. * Wed Apr 2 2014 Andrea Veri <averi@fedoraproject.org> - 1.2.4p1-1 - New upstream release. Fixes the missing two CVEs that were still left unfixed on 1.2.4: - CVE-2014-2330 - CVE-2014-2331 * Tue Mar 25 2014 Andrea Veri <averi@fedoraproject.org> - 1.2.4-1 - New upstream release. Fixes the following CVEs: - CVE-2014-2329 - CVE-2014-2332 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1101669 - CVE-2014-0243 check-mk: arbitrary file disclosure flaw as root https://bugzilla.redhat.com/show_bug.cgi?id=1101669 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update check-mk' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...