Overview

Request 547333 superseded

This nagios update fixes three vulnerabilities and one
configuration issue:

+ CVE-2016-8641: fix a possible symlink attack for files/dirs
created by root (bsc#1011630 and bsc#1018047)

+ CVE-2016-0726: remove the pre-configured administrative
account with fixed password from the htpasswd file and
provide an empty one instead (boo#961115)

+ CVE-2016-9565: fix remote command injection by MITM the
RSS feeds (boo#1015744)

+ fix apache configuration to work also with latest
apache 2.4 (boo#984116)

Request History
Lars Vogdt's avatar

lrupp created request

This nagios update fixes three vulnerabilities and one
configuration issue:

+ CVE-2016-8641: fix a possible symlink attack for files/dirs
created by root (bsc#1011630 and bsc#1018047)

+ CVE-2016-0726: remove the pre-configured administrative
account with fixed password from the htpasswd file and
provide an empty one instead (boo#961115)

+ CVE-2016-9565: fix remote command injection by MITM the
RSS feeds (boo#1015744)

+ fix apache configuration to work also with latest
apache 2.4 (boo#984116)


Maintenance Bot's avatar

maintbot accepted review

ok


Maintenance Bot's avatar

maintbot approved review

ok


Andreas Stieger's avatar

AndreasStieger superseded request

newer request

openSUSE Build Service is sponsored by