Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

SUSE: 2014:0682-1 Important: Remote Command Execution in Nagios-NRPE

suse
Calendar Grey May 20, 2014
Scroller Suse
An urgent security patch for nagios-nrpe mitigates potential remote execution vulnerabilities on SUSE platforms.
An update that fixes one vulnerability is now available

Summary

nagios-nrpe has been updated to prevent possible remote command execution when command arguments are enabled. This issue affects versions 2.15 and older. Further information is available at https://seclists.org/fulldisclosure/2014/Apr/240 These security issues have been fixed: * Remote command execution (CVE-2014-2913) Security Issue references: * CVE-2014-2913 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11 SP3 for VMware: zypper in -t patch slessp3-nagios-nrpe-9204 - SUSE Linux Enterprise Server 11 SP3:

References

#874743

Cross- CVE-2014-2913

Affected Products:

SUSE Linux Enterprise Server 11 SP3 for VMware

SUSE Linux Enterprise Server 11 SP3

https://www.suse.com/security/cve/CVE-2014-2913.html

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0682-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.