nagios security update

statusmap.cgi and config.cgi were prone to cross-site
scripting (XSS) vulnerabilities (CVE-2011-1523,
CVE-2011-2179).

Fixed bugs
bnc#682966
VUL-0: Nagios: XSS in the network status map CGI script
bnc#697895
VUL-0: nagios: XSS in config.c
CVE#CVE-2011-1523
Cross-site scripting (XSS) vulnerability in statusmap.c in statusmap.cgi in Nagios 3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the layer parameter.
CVE#CVE-2011-2179
Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in (1) Nagios 3.2.3 and (2) Icinga before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the expand parameter, as demonstrated by an (a) command action
Selected Binaries
openSUSE Build Service is sponsored by