CVE-2013-7107

NameCVE-2013-7107
DescriptionCross-site request forgery (CSRF) vulnerability in cmd.cgi in Icinga 1.8.5, 1.9.4, 1.10.2, and earlier allows remote attackers to hijack the authentication of users for unspecified commands via unspecified vectors, as demonstrated by bypassing authentication requirements for CVE-2013-7106.
SourceCVE (at NVD; LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-2956-1
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
icinga (PTS)wheezy (security), wheezy1.7.1-7fixed
jessie1.11.6-1fixed
stretch, sid1.13.3-2fixed
nagios3 (PTS)wheezy3.4.1-3+deb7u1vulnerable
wheezy (security)3.4.1-3+deb7u2vulnerable
jessie3.5.1.dfsg-2vulnerable
stretch, sid3.5.1.dfsg-2.1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
icingasource(unstable)1.10.2-1low
icingasourcewheezy1.7.1-7mediumDSA-2956-1
nagios3source(unstable)(unfixed)low

Notes

[squeeze] - icinga <no-dsa> (Minor issue)
[jessie] - nagios3 <no-dsa> (Minor issue)
[squeeze] - nagios3 <no-dsa> (Minor issue)
[wheezy] - nagios3 <no-dsa> (Minor issue)
https://dev.icinga.org/issues/5346

Search for package or bug name: Reporting problems