Startseite ▼ Bookkeeping
Online ▼ Sicherheits
Überprüfungs ▼
Verwaltetes
DNS ▼
Info
Bestellen/Erneuern
FAQ
AUP
Dynamic DNS Clients
Domaine konfigurieren Dyanmic DNS Update Password Netzwerk
Überwachung ▼
Enterprise
Erweiterte
Standard
Gratis Test
FAQ
Preis/Funktionszusammenfassung
Bestellen
Beispiele
Konfigurieren/Status Alarm Profile | |||
Test Kennung: | 1.3.6.1.4.1.25623.1.0.850460 |
Kategorie: | SuSE Local Security Checks |
Titel: | openSUSE: Security Advisory for NRPE (openSUSE-SU-2013:0624-1) |
Zusammenfassung: | The remote host is missing an update for the 'NRPE'; package(s) announced via the referenced advisory. |
Beschreibung: | Summary: The remote host is missing an update for the 'NRPE' package(s) announced via the referenced advisory. Vulnerability Insight: NRPE (the Nagios Remote Plug-In Executor) allows the passing of $() to plugins/scripts which, if run under bash, will execute that shell command under a subprocess and pass the output as a parameter to the called script. Using this, it is possible to get called scripts, such as check_http, to execute arbitrary commands under the uid that NRPE/nagios is running as (typically, 'nagios'). With this update NRPE will deny remote requests containing a bash command substitution. Affected Software/OS: NRPE on openSUSE 11.4 Solution: Please install the updated package(s). CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2013-1362 Bugtraq: 20130221 OSEC-2013-01: nagios metacharacter filtering omission (Google Search) http://seclists.org/bugtraq/2013/Feb/119 http://www.exploit-db.com/exploits/24955 http://www.occamsec.com/vulnerabilities.html#nagios_metacharacter_vulnerability SuSE Security Announcement: openSUSE-SU-2013:0621 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00005.html SuSE Security Announcement: openSUSE-SU-2013:0624 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00006.html |
Copyright | Copyright (C) 2013 Greenbone Networks GmbH |
Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |