copyright | disclaimer | privacy | contact  
Australia's Leading Computer Emergency Response Team
 
Search this site

 
On this site

 > HOME
 > About AusCERT
 > Membership
 > Contact Us
 > PKI Services
 > Publications
 > Sec. Bulletins
 > Conferences
 > News & Media
 > Services
 > Web Log
 > Site Map
 > Site Help
 > Member login





 

ESB-2014.0772 - [UNIX/Linux][Mandriva] nagios: Denial of service - Remote/unauthenticated

Date: 20 May 2014
References: ESB-2014.0959  

Click here for printable version
Click here for PGP verifiable version
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2014.0772
            Updated nagios packages fix security vulnerability
                                20 May 2014

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           nagios
Publisher:         Mandriva
Operating System:  Mandriva Linux
                   UNIX variants (UNIX, Linux, OSX)
Impact/Access:     Denial of Service -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2014-1878  

Original Bulletin: 
   http://advisories.mageia.org/MGASA-2014-0186.html

Comment: This advisory references vulnerabilities in products which run on 
         platforms other than Mandriva. It is recommended that administrators
         running nagios check for an updated version of the software for 
         their operating system.

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

 _______________________________________________________________________

 Mandriva Linux Security Advisory                         MDVSA-2014:089
 http://www.mandriva.com/en/support/security/
 _______________________________________________________________________

 Package : nagios
 Date    : May 16, 2014
 Affected: Business Server 1.0, Enterprise Server 5.0
 _______________________________________________________________________

 Problem Description:

 Updated nagios packages fix security vulnerability:
 
 Stack-based buffer overflow in the cmd_submitf function in cgi/cmd.c in
 Nagios Core, possibly 4.0.3rc1 and earlier, and Icinga before 1.8.6,
 1.9 before 1.9.5, and 1.10 before 1.10.3 allows remote attackers to
 cause a denial of service (segmentation fault) via a long message to
 cmd.cgi (CVE-2014-1878).
 _______________________________________________________________________

 References:

 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1878
 http://advisories.mageia.org/MGASA-2014-0186.html
 _______________________________________________________________________

 Updated Packages:

 Mandriva Enterprise Server 5:
 60ce30af7d5d0577113a3eb7b5b9590f  mes5/i586/nagios-3.1.2-0.6mdvmes5.2.i586.rpm
 0be8bdf78c4a16041f8cb40ecd32a686  mes5/i586/nagios-devel-3.1.2-0.6mdvmes5.2.i586.rpm
 26f04c99f2e0dd36c07ff5baceaf5da5  mes5/i586/nagios-theme-default-3.1.2-0.6mdvmes5.2.i586.rpm
 c5a82025b52d15d7c1baf75662a2ca76  mes5/i586/nagios-www-3.1.2-0.6mdvmes5.2.i586.rpm 
 b5f59cfd77c07623a4d620154acca490  mes5/SRPMS/nagios-3.1.2-0.6mdvmes5.2.src.rpm

 Mandriva Enterprise Server 5/X86_64:
 552d4af54e7876595c9ae6dd47948498  mes5/x86_64/nagios-3.1.2-0.6mdvmes5.2.x86_64.rpm
 79544ceabd1a5ddfeb75dbdc9174eed4  mes5/x86_64/nagios-devel-3.1.2-0.6mdvmes5.2.x86_64.rpm
 cac41076c80a3fccb93449074350604c  mes5/x86_64/nagios-theme-default-3.1.2-0.6mdvmes5.2.x86_64.rpm
 446e5864242d2d8e7f57307d7a416eca  mes5/x86_64/nagios-www-3.1.2-0.6mdvmes5.2.x86_64.rpm 
 b5f59cfd77c07623a4d620154acca490  mes5/SRPMS/nagios-3.1.2-0.6mdvmes5.2.src.rpm

 Mandriva Business Server 1/X86_64:
 37d46d71b801a1d04f391e38cd7a0b5d  mbs1/x86_64/nagios-3.4.4-4.2.mbs1.x86_64.rpm
 a97d21062a8ac761fbb700680b62d1e5  mbs1/x86_64/nagios-devel-3.4.4-4.2.mbs1.x86_64.rpm
 e9c38f5c88d82340db0a48b49f60a1d2  mbs1/x86_64/nagios-www-3.4.4-4.2.mbs1.x86_64.rpm 
 8be9920434af8bb841aec5e6fbb5a95c  mbs1/SRPMS/nagios-3.4.4-4.2.mbs1.src.rpm
 _______________________________________________________________________

 To upgrade automatically use MandrivaUpdate or urpmi.  The verification
 of md5 checksums and GPG signatures is performed automatically for you.

 All packages are signed by Mandriva for security.  You can obtain the
 GPG public key of the Mandriva Security Team by executing:

  gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

 You can view other update advisories for Mandriva Linux at:

  http://www.mandriva.com/en/support/security/advisories/

 If you want to report vulnerabilities, please contact

  security_(at)_mandriva.com
 _______________________________________________________________________

 Type Bits/KeyID     Date       User ID
 pub  1024D/22458A98 2000-07-10 Mandriva Security Team
  <security*mandriva.com>
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iD8DBQFTdclWmqjQ0CJFipgRAqSxAKCj7ky1+IXRRrqJg+OvAzxzJcO0ogCeMUKh
1PWb4f9MSwRNuAKQRYoYUPs=
=h2w/
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBU3r3MxLndAQH1ShLAQIrRRAAlcBgvmVY5fNmSip9uQUv78f10nTJVZ9h
DrxQe7yXB6vF1fvVo6Zd/VPdcXdewQs0WNxPL0SWFHWeKCwDWERj5GUajR2cl7qJ
7gwbdw761jJeokVU4PWywdG2HsfKACM3JBlMDYHb4VpKebwWOoiyst/dJFXxVXM0
i0qXpVlp6LEAig8gSNRbKWOLnSwqhgJElfFMjX0CdZ7b5Wec1uKkd13wpfF/fLLW
BFufxvYOxO9rt6H5cA4OAoN32nlZOQ+kVriDxrWMLWtFbX/dmCpKtRi3J3aBAv7x
zPqIw5kKF8lcq4gIMgHyd2rbVEAz/LFAHpINMjUpKBNqZa+Fyuf/V2d9Vp6tqQ+x
7PQhLwSoIBgEbAs3UCzMDyx5/1erIiuDsNQ5Cc+vJAWgjunouYC5Qo5g/Lf69e7U
NvNpkugF3DoGmShCCam6ydRSxwTTx1ha+/jL2vjq26rDT6gn5FbYM+1ie7oQ/jcU
WRhpr59b/kewf3AxVQNXnCW5SYZuta4QtYaNcZIK0eoBOfYwrPYtc+Jeb0WgvBwu
xNLxmvH6Dab27dTFsdeomvZcEG15trNt49hBXx5hbRPiQqDJZDg0ID4GghaT45Dm
hmaZkXQg7mIrAuqPHY2hJaRnA9Dotk/WJsNBREaP2yIaT780MSWNzMyshkkuXUcV
BefMRxX3Znk=
=erX7
-----END PGP SIGNATURE-----