Inicial ▼ Bookkeeping
Online ▼ Auditorias ▼
DNS
Administrado ▼
Acerca de DNS
Ordenar/Renovar
Preguntas Frecuentes
AUP
Dynamic DNS Clients
Configurar Dominios Dynamic DNS Update Password Monitoreo
de Redes ▼
Enterprise
Avanzado
Estándarr
Prueba
Preguntas Frecuentes
Resumen de Precio/Funciones
Ordenar
Muestras
Configure/Status Alert Profiles | |||
ID de Prueba: | 1.3.6.1.4.1.25623.1.0.850457 |
Categoría: | SuSE Local Security Checks |
Título: | openSUSE: Security Advisory for NRPE (openSUSE-SU-2013:0621-1) |
Resumen: | The remote host is missing an update for the 'NRPE'; package(s) announced via the referenced advisory. |
Descripción: | Summary: The remote host is missing an update for the 'NRPE' package(s) announced via the referenced advisory. Vulnerability Insight: NRPE (the Nagios Remote Plug-In Executor) allows the passing of $() to plugins/scripts which, if run under bash, will execute that shell command under a subprocess and pass the output as a parameter to the called script. Using this, it is possible to get called scripts, such as check_http, to execute arbitrary commands under the uid that NRPE/nagios is running as (typically, 'nagios'). With this update NRPE will deny remote requests containing a bash command substitution. Affected Software/OS: NRPE on openSUSE 12.2, openSUSE 12.1 Solution: Please install the updated package(s). CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Referencia Cruzada: |
Common Vulnerability Exposure (CVE) ID: CVE-2013-1362 Bugtraq: 20130221 OSEC-2013-01: nagios metacharacter filtering omission (Google Search) http://seclists.org/bugtraq/2013/Feb/119 http://www.exploit-db.com/exploits/24955 http://www.occamsec.com/vulnerabilities.html#nagios_metacharacter_vulnerability SuSE Security Announcement: openSUSE-SU-2013:0621 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00005.html SuSE Security Announcement: openSUSE-SU-2013:0624 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00006.html |
Copyright | Copyright (C) 2013 Greenbone Networks GmbH |
Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |