Release date:
Updated on:
Affected Systems:
Nagios Remote Plugin Executor (NRPE) <= 2.15
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-2913
Nagios is an open-source computer system monitoring, network monitoring, and architecture monitoring software.
Nagios Remote Plugin Executor (NRPE) 2.15 and earlier versions of nrpe. c has an incomplete blacklist vulnerability, which allows remote attackers to execute arbitrary commands by using the new line characters in the-a option of libexec/check_nrpe.
Network Monitor Nagios Overview
Nagios construction and Configuration
Build a Nagios monitoring platform in the Nginx Environment
Configure the basic Nagios System on RHEL5.3 (using Nagios-3.1.2)
CentOS 5.5 + Nginx + Nagios monitoring and control terminal installation and Configuration Guide
Install Nagios Core for Ubuntu 13.10 Server
<* Source: vendor
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Nagios
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.nagios.org/
Refer:
Http://lists.opensuse.org/opensuse-updates/2014-05/msg00014.html
Http://lists.opensuse.org/opensuse-updates/2014-05/msg00005.html
Http://seclists.org/fulldisclosure/2014/Apr/242
Nagios details: click here
Nagios: click here
This article permanently updates the link address: