openSUSE-SU-2021:0715-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:0715-1
openSUSE-SU-2021:0715-1
Summary: Security update for nagios
Details: This update for nagios fixes the following issues: - new nagios-exec-start-post script to fix boo#1003362 - fix nagios_upgrade.sh writing to log file in user controlled directory (boo#1182398). The nagios_upgrade.sh script writes the logfile directly below /var/log/ nagios was updated to 4.4.6: * Fixed Map display in Internet Explorer 11 (#714) * Fixed duplicate properties appearing in statusjson.cgi (#718) * Fixed NERD not building when enabled in ./configure (#723) * Fixed build process when using GCC 10 (#721) * Fixed postauth vulnerabilities in histogram.js, map.js, trends.js (CVE-2020-13977, boo#1172794) * When using systemd, configuration will be verified before reloading (#715) * Fixed HARD OK states triggering on the maximum check attempt (#757) * Fix for CVE-2016-6209 (boo#989759) - The 'corewindow' parameter (as in bringing this to our attention go to Dawid Golunski (boo#1014637)
References: https://lists.opensuse.org/archives/list/[email protected]/thread/RCXDSKLLDI4CG7PLAOOYGYVNNNQLL5WP/, https://bugzilla.suse.com/1003362, https://bugzilla.suse.com/1014637, https://bugzilla.suse.com/1172794, https://bugzilla.suse.com/1182398, https://bugzilla.suse.com/989759, https://www.suse.com/security/cve/CVE-2016-6209, https://www.suse.com/security/cve/CVE-2020-13977
Affected packages
Package
Name: nagios
Purl: pkg:rpm/opensuse/nagios&distro=openSUSE%20Leap%2015.2
Affected ranges
Type: ECOSYSTEM
Events:
