USN-795-1: Nagios vulnerability

2 July 2009

nagios2, nagios3 vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 9.04
  • Ubuntu 8.10
  • Ubuntu 8.04 LTS

Software Description

  • nagios3
  • nagios2

Details

It was discovered that Nagios did not properly parse certain commands submitted using the WAP web interface. An authenticated user could exploit this flaw and execute arbitrary programs on the server.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 9.04
nagios3 - 3.0.6-2ubuntu1.1
Ubuntu 8.10
nagios3 - 3.0.2-1ubuntu1.2
Ubuntu 8.04 LTS
nagios2 - 2.11-1ubuntu1.5

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

After a standard system upgrade you need to restart Nagios to effect the necessary changes.

References