Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

openSUSE: 2013:0621-1 Important: NRPE Metacharacter Filtering Issue

opensuse
Calendar Grey April 4, 2013
Dist Opensuse Esm H88
Stay protected against a critical vulnerability in NRPE for openSUSE by updating your version, reviewing configurations, and securing your system
An update that fixes one vulnerability is now available

Description

NRPE (the Nagios Remote Plug-In Executor) allows the

passing of $() to plugins/scripts which, if run under bash,

will execute that shell command under a subprocess and pass

the output as a parameter to the called script. Using this,

it is possible to get called scripts, such as check_http,

to execute arbitrary commands under the uid that

NRPE/nagios is running as (typically, 'nagios').

With this update NRPE will deny remote requests containing

a bash command substitution.

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 12.2:

zypper in -t patch openSUSE-2013-301

- openSUSE 12.1:

zypper in -t patch openSUSE-2013-301

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 12.2 (i586 x86_64):

nagios-nrpe-2.12-30.9.1

nagios-nrpe-debuginfo-2.12-30.9.1

nagios-nrpe-debugsource-2.12-30.9.1

nagios-nrpe-doc-2.12-30.9.1

nagios-plugins-nrpe-2.12-30.9.1

nagios-plugins-nrpe-debuginfo-2.12-30.9.1

- openSUSE 12.1 (i586 x86_64):

nagios-nrpe-2.12-27.7.1

nagios-nrpe-debuginfo-2.12-27.7.1

nagios-nrpe-debugsource-2.12-27.7.1

nagios-nrpe-doc-2.12-27.7.1

nagios-plugins-nrpe-2.12-27.7.1

nagios-plugins-nrpe-debuginfo-2.12-27.7.1

References

https://www.suse.com/security/cve/CVE-2013-1362.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2013:0621-1
Rating: important
Affected Products: openSUSE 12.2 openSUSE 12.1 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here