CVE-2013-4214

NameCVE-2013-4214
Descriptionrss-newsfeed.php in Nagios Core 3.4.4, 3.5.1, and earlier, when MAGPIE_CACHE_ON is set to 1, allows local users to overwrite arbitrary files via a symlink attack on /tmp/magpie_cache.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium
Debian Bugs719056

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nagios3 (PTS)jessie3.5.1.dfsg-2fixed
jessie (security)3.5.1.dfsg-2+deb8u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nagios3source(unstable)3.5.1-1low719056
nagios3sourcesqueeze(not affected)

Notes

[wheezy] - nagios3 <no-dsa> (Minor issue)
[squeeze] - nagios3 <not-affected> (html/rss-newsfeed.php not present)
fixed by removing html/rss-newsfeed.php completely
http://anonscm.debian.org/gitweb/?p=pkg-nagios/pkg-nagios3.git;a=commit;h=c88bef82308c99601732bb9517a1af5bc6928282

Search for package or bug name: Reporting problems