Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 481
Alerts This Week
Warning Icon 1 481

Red Hat Enterprise: RHSA-2017:0214-01 Critical Risk in Nagios Command Exec

red hat
Calendar Grey January 31, 2017
Scroller Redhat
Crucial security patch for Nagios in Red Hat OpenStack Platform 7 addresses vulnerabilities related to remote command execution and access management issues.
An update for nagios is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

Nagios is a program that monitors hosts and services on your network, and has the ability to send email or page alerts when a problem arises or is resolved. Nagios is written in C and designed to run under Linux (and some other *NIX variants) as a background process, intermittently running checks on various services that you specify. The actual service checks are performed by separate "plugin" programs which return the status of the checks to Nagios. Nagios plugins are available at https://sourceforge.net/projects/nagios-4-debian-plugins/ This package provides the core program, web interface, and documentation files for Nagios. Development files are built as a separate package.
Security Fix(es):
* Various command-execution flaws were found in the Snoopy library included with Nagios. These flaws allowed remote attackers to execute arbitrary commands by manipulating Nagios HTTP headers. (CVE-2008-7313, CVE-2014-5008, CVE-2014-5009)
* It was found that an attacker who could control the content of an RSS feed could execute code remotely using the Nagios web interface. This flaw could be used to gain access to the remote system and in some scenarios control over the system. (CVE-2016-9565)
* A privileges flaw was found in Nagios where log files were unsafely handled. An attacker who could control Nagios logging configuration ('nagios' user/group) could exploit the flaw to elevate their access to that of a privileged user. (CVE-2016-9566)
Red Hat would like to thank Dawid Golunski for reporting CVE-2016-9565 and CVE-2016-9566.

References

https://access.redhat.com/security/cve/CVE-2008-7313 https://access.redhat.com/security/cve/CVE-2014-5008 https://access.redhat.com/security/cve/CVE-2014-5009 https://access.redhat.com/security/cve/CVE-2016-9565 https://access.redhat.com/security/cve/CVE-2016-9566 https://access.redhat.com/security/updates/classification#important

Package List

Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7:
Source: nagios-3.5.1-9.el7.src.rpm
x86_64: nagios-3.5.1-9.el7.x86_64.rpm nagios-common-3.5.1-9.el7.x86_64.rpm nagios-debuginfo-3.5.1-9.el7.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2017:0214-01
Product: Red Hat Enterprise Linux OpenStack Platform
Issue date: 2017-01-31

Topic

An update for nagios is now available for Red Hat Enterprise LinuxOpenStack Platform 7.0 (Kilo) for RHEL 7.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 - x86_64

Bugs Fixed

1121497 - CVE-2008-7313 CVE-2014-5008 CVE-2014-5009 snoopy: incomplete fixes for command execution flaws

1402869 - CVE-2016-9566 nagios: Privilege escalation issue

1405363 - CVE-2016-9565 nagios: Command injection via curl in MagpieRSS

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.