Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 7 Security Update: MGASA-2020-0247 for NRPE Issues

mageia
Calendar Grey June 10, 2020
Dist Mageia Esm H88
Mageia 2020-0248 provides information on a critical update for vsftpd that resolves vulnerabilities related to denial of service and arbitrary file overwrite problems.
Advisory text to describe the update

Summary

Advisory text to describe the update. Wrap lines at ~75 chars.
Updated nrpe packages fix security vulnerabilities:
Nagios NRPE 3.2.1 has Insufficient Filtering because, for example, nasty_metachars interprets \n as the character \ and the character n (not as the \n newline sequence). This can cause command injection (CVE-2020-6581).
Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call (CVE-2020-6582).

References

- https://bugs.mageia.org/show_bug.cgi?id=26482

- https://herolab.usd.de/security-advisories/usd-2020-0001/

- https://herolab.usd.de/security-advisories/usd-2020-0002/

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/4HL6LSLRKKPUIY2PIWFGZ7QMM7FKARMR/

- https://www.cve.org/CVERecord?id=CVE-2020-6581

- https://www.cve.org/CVERecord?id=CVE-2020-6582

Resolution

SRPMS

- 7/core/nrpe-3.2.1-3.2.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 10 Jun 2020
URL: https://advisories.mageia.org/MGASA-2020-0247.html
Type: security
CVE: CVE-2020-6581, CVE-2020-6582

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here