Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
87

Debian 3.1 DSA-1495-2 Critical: Remote Buffer Overflow in Nagios Plugins

Several local/remote vulnerabilities have been discovered in two of the plugins for the Nagios network monitoring and management system. The Common Vulnerabilities and Exposures project identifies the following problems: . - ------------------------------------------------------------------------Debian Security Advisory DSA-1495-2 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff February 17, 2008 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : nagios-plugins Vulnerability : buffer overflows Problem type : remote Debian-specific: no CVE Id(s) : CVE-2007-5198 CVE-2007-5623 A problem with the build system of the nagios-plugins package from old stable (Sarge) lead to check_procs not being included for the i386 architecture. This update fixes this regression. For reference the original advisory text below: Several local/remote vulnerabilities have been discovered in two of the plugins for the Nagios network monitoring and management system. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-5198 A buffer overflow has been discovered in the parser for HTTP Location headers (present in the check_http module). CVE-2007-5623 A buffer overflow has been discovered in the check_snmp module. For the stable distribution (etch), these problems have been fixed in version 1.4.5-1etch1. For the old stable distribution (sarge), these problems have been fixed in version 1.4-6sarge2. We recommend that you upgrade your nagios-plugins package. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian 3.1 (oldstable) - ----------------------Oldstable updates are available for alpha, amd64, arm, hppa, i386, ia64, m68k, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 927 51eb15268f75ef4f4271d33706c92029 Size/MD5 checksum: 973910 d46ae53154a228614629d50ea56d46b6 Size/MD5 checksum: 22422 573798e3cce46bf2b5d0206472db13f8 alpha architecture (DEC Alpha) Size/MD5 checksum: 514752 f4931888fbe7aa359fe68adc160e1429 amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 395950 a5450650d11dddf74e6379165b069308 arm architecture (ARM) Size/MD5 checksum: 379384 76bcf58893f373e308afa4ec1f10b278 hppa architecture (HP PA RISC) Size/MD5 checksum: 393034 f37e7bcc007c031c593dd77bb1b0cb7d i386 architecture (Intel ia32) Size/MD5 checksum: 384998 d536fe6fbae4b376325984e3f3739572 ia64 architecture (Intel ia64) Size/MD5 checksum: 644450 e732ba3933eaa34c98d365586dbe84d5 m68k architecture (Motorola Mc680x0) Size/MD5 checksum: 336632 5f48a57884094ae79c07f861ff4839f0 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 544968 55a7bb6628e93c37090846f58cafa432 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 532950 48493d1a8ddbcd3715fbfba6c9186681 powerpc architecture (PowerPC) Size/MD5 checksum: 367814 142d28f8c6aff94a72f6b19d0501f1ac s390 architecture (IBM S/390) Size/MD5 checksum: 372306 f564fa8e28ec10b7cbbfacffbd9229ab sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 349258 907911b940ffc915095dadf9c97d5f2c These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: debhttps://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The Ubuntu Security Notice USN-4551-1 tackles a critical vulnerability in the apache2-server. Immediate action advised.. Debian Security, Nagios Plugins, Buffer Overflow. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 17, 2008 Critical Debian
87

Debian 4.0 DSA-1495-1 Critical: Nagios Plugins Remote Buffer Overflow

A buffer overflow has been discovered in the parser for HTTP Location headers (present in the check_http module).. - ------------------------------------------------------------------------Debian Security Advisory DSA-1495-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff February 12, 2008 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : nagios-plugins Vulnerability : buffer overflows Problem type : remote Debian-specific: no CVE Id(s) : CVE-2007-5198 CVE-2007-5623 Several local/remote vulnerabilities have been discovered in two of the plugins for the Nagios network monitoring and management system. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-5198 A buffer overflow has been discovered in the parser for HTTP Location headers (present in the check_http module). CVE-2007-5623 A buffer overflow has been discovered in the check_snmp module. For the stable distribution (etch), these problems have been fixed in version 1.4.5-1etch1. For the old stable distribution (sarge), these problems have been fixed in version 1.4-6sarge1. We recommend that you upgrade your nagios-plugins package. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian 3.1 (oldstable) - ----------------------Oldstable updates are available for alpha, amd64, arm, hppa, i386, ia64, m68k, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 927 bd96c045610c5978605f2afc9dfb987c Size/MD5 checksum: 21778 74cd27a521e5e7654cf2391aeee2deac Size/MD5 checksum: 973910 d46ae53154a228614629d50ea56d46b6 alpha architecture (DEC Alpha) Size/MD5 checksum: 514580 83623f3e2d62171a7e0f515283f437be amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 395554 3e8bb19e0b8de1078a306fd7761fe5c1 arm architecture (ARM) Size/MD5 checksum: 379032 32300cc77a09ad8cdf55a2dfa5f7bc37 hppa architecture (HP PA RISC) Size/MD5 checksum: 392784 3e9f60bcc439f4bfd2854258c1f62d1a i386 architecture (Intel ia32) Size/MD5 checksum: 334198 f045b9c68b6b1c791ffd5f1aaf89606e ia64 architecture (Intel ia64) Size/MD5 checksum: 644134 640619b6d69d316a85e903b4042fafe0 m68k architecture (Motorola Mc680x0) Size/MD5 checksum: 336368 a5aea6422c93b79aec327446ae3e417b mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 544780 c5b5d8c8e7c1a35121664d0aa0995880 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 532688 a50f57072f656ab46a68d6fc4efc993b powerpc architecture (PowerPC) Size/MD5 checksum: 367568 a35ec66bd965bcef9ca041278405df44 s390 architecture (IBM S/390) Size/MD5 checksum: 372064 0b3e8860d95b81c9c0f163006926613f sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 349018 97a0f07fc2aa948921065c926bd3497c Debian 4.0 (stable) - -------------------Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 1285997 359afddaf6a8e3228a5130b60bed0f67 Size/MD5 checksum: 21859 58658037a3a2cdf6531246d4c6f3ac6b Size/MD5 checksum: 1033 4665beadc7b3be6ac31244bc96deeafb alpha architecture (DEC Alpha) Size/MD5 checksum: 639288 faad3564117ca60e315e7598cc839adf Size/MD5 checksum: 80854 59e15a8a67c4177dfb36feee67d1866b Size/MD5 checksum: 288820 cd421951ee33047f61068bd03ee05677 amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 537840 a97a4c671db575426a7c8d3c9211fb8d Size/MD5 checksum: 245170 482ad5f0d233d6fd4efe945dfb372ef6 Size/MD5 checksum: 80276 ea35ab0beb77c38a5cfeda5f84d25d26 arm architecture (ARM) Size/MD5 checksum: 225412 80809d122ffef7863ff15ccab6a8759f Size/MD5 checksum: 472236 15a27bbcaccc3dd7d79e226c61456c5e Size/MD5 checksum: 80906 5d38cd759f2bb1da5094c9ef6c6363e4 hppa architecture (HP PA RISC) Size/MD5 checksum: 80354 11649afbd71868b06f8aaadccbda33bd Size/MD5 checksum: 520106 cba264378269730770844d8bc8ddfaa5 Size/MD5 checksum: 234750 f96394409146a183dc9572aff62d1fa3 i386 architecture (Intel ia32) Size/MD5 checksum: 217304 4f364a99c8d29939930e17b586bd7163 Size/MD5 checksum: 80356 55f8c942983a877f3f81694870a555cc Size/MD5 checksum: 470394 3a973e79925f8ba0d452843e53eb6418 ia64 architecture (Intel ia64) Size/MD5 checksum: 80356 98903ee6cfe0db798b72f631fd8abc5e Size/MD5 checksum: 833178 5cd28a54fd6b4982c63dbf31001575bd Size/MD5 checksum: 360550 b299c6b4cc32f2f8dbf98099097c0cd9 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 592006 8133ad978949b3dd27a8b135e42237d0 Size/MD5 checksum: 80234 ab53bbaf42b9330871432b364c7e1da4 Size/MD5 checksum: 270096 66e5f9ec3fd945b591fb81629e775b35 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 258108 90da4f6c80fab92b53e7aee163c6513f Size/MD5 checksum: 583182 888620e0ab476014e50103cf8c121c8b Size/MD5 checksum: 80352 c531e93967842f092fb3d17bb85d6285 powerpc architecture (PowerPC) Size/MD5 checksum: 571284 948635d992c8f31e62f138f1101a3439 Size/MD5 checksum: 80350 1af2e6bc171acd12b8ac77a0fc8da522 Size/MD5 checksum: 249124 79d4b0e36b2658cce9ad9a6f5d7065c9 s390 architecture (IBM S/390) Size/MD5 checksum: 80346 c5757ac42adb6885db11da7d57afc02a Size/MD5 checksum: 229434 5d09acd328ba96f9198a4fc994826cff Size/MD5 checksum: 503826 1ee5e9657e38c53e40a9418d64e3e83c sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 80350 de57d21d5c7ef817d10a6aa7b682b724 Size/MD5 checksum: 461116 bab05b0e3eb8c96f94193c180150cf57 Size/MD5 checksum: 212116 62c17dc86bf4f424c413d6bb2aff8b70 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A critical security flaw in the nagios-plugins for Debian platforms necessitates immediate patching to ensure system safety.. Debian Security,Nagios Monitoring,Buffer Overflow,Network Management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 12, 2008 Critical Debian
91

Gentoo: GLSA-200711-11 High: Nagios Plugins Remote Execution Threat

Two buffer overflow vulnerabilities in the Nagios Plugins might allow for remote execution of arbitrary code.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200711-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Nagios Plugins: Two buffer overflows Date: November 08, 2007 Bugs: #196308, #194178 ID: 200711-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Two buffer overflow vulnerabilities in the Nagios Plugins might allow for remote execution of arbitrary code. Background ========= The Nagios Plugins are an official set of plugins for Nagios, an open source host, service and network monitoring program. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-analyzer/nagios-plugins < 1.4.10-r1 > = 1.4.10-r1 Description ========== fabiodds reported a boundary checking error in the "check_snmp" plugin when processing SNMP "GET" replies that could lead to a stack-based buffer overflow (CVE-2007-5623). Nobuhiro Ban reported a boundary checking error in the redir() function of the "check_http" plugin when processing HTTP "Location:" header information which might lead to a buffer overflow (CVE-2007-5198). Impact ===== A remote attacker could exploit these vulnerabilities to execute arbitrary code with the privileges of the user running Nagios or cause a Denial of Service by (1) sending a specially crafted SNMP "GET" reply to the Nagios daemon or (2) sending an overly long string in the "Location:"header of an HTTP reply. Note that to exploit (2), the malicious or compromised web server has to be configured in Nagios and the "-f" (follow) option has to be enabled. Workaround ========= There is no known workaround at this time. Resolution ========= All users of the Nagios Plugins should upgrade to the latest version: # emerge --sync # emerge -av --oneshot "> =net-analyzer/nagios-plugins-1.4.10-r1" References ========= [ 1 ] CVE-2007-5198 https://www.cve.org/CVERecord?id=CVE-2007-5198 [ 2 ] CVE-2007-5623 https://www.cve.org/CVERecord?id=CVE-2007-5623 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200711-11 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2007 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (GNU/Linux) Comment: Using GnuPG with Mozilla - iD8DBQFHM2DVuhJ+ozIKI5gRAn38AJ98L27Sde9S5ebhZYWNt+je89v1UACffi8l CeAHOSuc4Z2xQ9nFp6T8a20=IvZ2 -----END PGP SIGNATURE----- . Recent vulnerabilities in Nagios Plugins on Gentoo reveal two critical buffer overflow flaws that may allow for remote code execution. Users are urged to update without delay.. Remote Code Execution, Nagios Plugins, Gentoo Security Advisory. . LinuxSecurity.com Team

Calendar%202 Nov 08, 2007 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200