Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

openSUSE 11.4: 2013:0624-1 Important: NRPE Command Execution Issue

opensuse
Calendar Grey April 4, 2013
Dist Opensuse Esm H88
openSUSE has released a crucial security update that rectifies the NRPE metacharacter filtering oversight, thereby improving security measures and applying an essential patch.
An update that fixes one vulnerability is now available.

Description

NRPE (the Nagios Remote Plug-In Executor) allows the

passing of $() to plugins/scripts which, if run under bash,

will execute that shell command under a subprocess and pass

the output as a parameter to the called script. Using this,

it is possible to get called scripts, such as check_http,

to execute arbitrary commands under the uid that

NRPE/nagios is running as (typically, 'nagios').

With this update NRPE will deny remote requests

containing a bash command substitution.

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 11.4:

zypper in -t patch 2013-55

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 11.4 (i586 x86_64):

nagios-nrpe-2.12-25.2

nagios-nrpe-debuginfo-2.12-25.2

nagios-nrpe-debugsource-2.12-25.2

nagios-nrpe-doc-2.12-25.2

nagios-plugins-nrpe-2.12-25.2

nagios-plugins-nrpe-debuginfo-2.12-25.2

References

https://www.suse.com/security/cve/CVE-2013-1362.html

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2013:0624-1
Rating: important
Affected Products: openSUSE 11.4

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here