Name | CVE-2013-4214 |
Description | rss-newsfeed.php in Nagios Core 3.4.4, 3.5.1, and earlier, when MAGPIE_CACHE_ON is set to 1, allows local users to overwrite arbitrary files via a symlink attack on /tmp/magpie_cache. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 719056 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
nagios3 | source | squeeze | (not affected) | |||
nagios3 | source | (unstable) | 3.5.1-1 | low | 719056 |
[wheezy] - nagios3 <no-dsa> (Minor issue)
[squeeze] - nagios3 <not-affected> (html/rss-newsfeed.php not present)
fixed by removing html/rss-newsfeed.php completely
http://anonscm.debian.org/gitweb/?p=pkg-nagios/pkg-nagios3.git;a=commit;h=c88bef82308c99601732bb9517a1af5bc6928282