Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 418
Alerts This Week
Warning Icon 1 418

Mageia 7 Security Update: MGASA-2020-0247 for NRPE Issues

mageia
Calendar Grey June 10, 2020
Scroller Mageia
Mageia 2020-0248 provides information on a critical update for vsftpd that resolves vulnerabilities related to denial of service and arbitrary file overwrite problems.
Advisory text to describe the update

Summary

Advisory text to describe the update. Wrap lines at ~75 chars.
Updated nrpe packages fix security vulnerabilities:
Nagios NRPE 3.2.1 has Insufficient Filtering because, for example, nasty_metachars interprets \n as the character \ and the character n (not as the \n newline sequence). This can cause command injection (CVE-2020-6581).
Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call (CVE-2020-6582).

References

- https://bugs.mageia.org/show_bug.cgi?id=26482

- https://herolab.usd.de/security-advisories/usd-2020-0001/

- https://herolab.usd.de/security-advisories/usd-2020-0002/

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/4HL6LSLRKKPUIY2PIWFGZ7QMM7FKARMR/

- https://www.cve.org/CVERecord?id=CVE-2020-6581

- https://www.cve.org/CVERecord?id=CVE-2020-6582

Resolution

SRPMS

- 7/core/nrpe-3.2.1-3.2.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 10 Jun 2020
URL: https://advisories.mageia.org/MGASA-2020-0247.html
Type: security
CVE: CVE-2020-6581, CVE-2020-6582

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.