Jump to content
Compatible Support Forums
Sign in to follow this  
news

LiteHawk QUATTRO NEON Drone Review @ ModSynergy.com

Recommended Posts

Package : nagios3

Version : 3.4.1-3+deb7u3

CVE ID : CVE-2016-9565 CVE-2016-9566

 

Nagios was found to be vulnerable to two security issues that, when

combined, lead to a remote root code execution vulnerability.

Fortunately, the hardened permissions of the Debian package limit the

effect of those to information disclosure, but privilege escalation to

root is still possible locally.

 

CVE-2016-9565

 

Improper sanitization of RSS feed input enables unauthenticated

remote read and write of arbitrary files which may lead to remote

code execution if the web root is writable.

 

CVE-2016-9566

 

Unsafe logfile handling allows unprivileged users to escalate their

privileges to root. In wheezy, this is possible only through the

debug logfile which is disabled by default.

 

For Debian 7 "Wheezy", these problems have been fixed in version

3.4.1-3+deb7u3.

 

We recommend that you upgrade your nagios3 packages.

 

Further information about Debian LTS security advisories, how to apply

these updates to your system and frequently asked questions can be

found at: https://wiki.debian.org/LTS

 

 

 

Share this post


Link to post

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
Sign in to follow this  

×