CVE-2013-7107

NameCVE-2013-7107
DescriptionCross-site request forgery (CSRF) vulnerability in cmd.cgi in Icinga 1.8.5, 1.9.4, 1.10.2, and earlier allows remote attackers to hijack the authentication of users for unspecified commands via unspecified vectors, as demonstrated by bypassing authentication requirements for CVE-2013-7106.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-2956-1
NVD severitymedium (attack range: remote, user-initiated)
Debian/oldstablepackages icinga, nagios3 are vulnerable.
Debian/stablepackage nagios3 is vulnerable.
Debian/testingpackage nagios3 is vulnerable.
Debian/unstablepackage nagios3 is vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
icinga (PTS)squeeze (security), squeeze1.0.2-2+squeeze1vulnerable
squeeze (lts)1.0.2-2+squeeze2vulnerable
wheezy, wheezy (security)1.7.1-7fixed
jessie, sid1.11.6-1fixed
nagios3 (PTS)squeeze (security), squeeze3.2.1-2+squeeze1vulnerable
wheezy3.4.1-3+deb7u1vulnerable
jessie, sid3.5.1.dfsg-2vulnerable

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
icingasource(unstable)1.10.2-1low
icingasourcewheezy1.7.1-7mediumDSA-2956-1
nagios3source(unstable)(unfixed)low

Notes

[squeeze] - icinga <no-dsa> (Minor issue)
[jessie] - nagios3 <no-dsa> (Minor issue)
[squeeze] - nagios3 <no-dsa> (Minor issue)
[wheezy] - nagios3 <no-dsa> (Minor issue)
https://dev.icinga.org/issues/5346

Search for package or bug name: Reporting problems