Security Advisory Important: nagios security update

Advisory: RHSA-2009:1141-1
Type: Security Advisory
Severity: Important
Issued on: 2009-07-02
Last updated on: 2009-07-02
Affected Products: Red Hat HPC Solution v.5 EL5
OVAL: N/A
CVEs (cve.mitre.org): CVE-2009-2288

Details

Updated nagios packages that fix one security issue are now available for
the Red Hat HPC Solution.

This update has been rated as having important security impact by the Red
Hat Security Response Team.

Nagios is a program that can monitor hosts and services on your network. It
can send email or page alerts when problems arise and when problems are
resolved.

A shell command injection flaw was discovered in the statuswml.cgi CGI
script used by Nagios. A remote attacker able to access Nagios web pages
could use this flaw to run arbitrary commands with the privileges of the
web server user (apache). (CVE-2009-2288)

Note: Successful authentication is required to access Nagios web pages. In
the Red Hat HPC Solution, configuration for Nagios is provided by the
kusu-nagios-config package, which creates a user with a fixed, default
password during installation. It is recommended to change this default
password, or restrict access to Nagios web pages based on a client's IP
address as is appropriate for your environment.

Users of nagios should upgrade to these updated packages, which contain a
backported patch to correct this issue.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

Updated packages

Red Hat HPC Solution v.5 EL5

SRPMS:
nagios-2.12-3.el5.src.rpm     68c87db95ed2e8e1355a5337ec7d94c3
 
x86_64:
nagios-2.12-3.el5.x86_64.rpm     e57c09f6062e9a984797f167222909e1
nagios-devel-2.12-3.el5.x86_64.rpm     d246b7ec8d16e6ef18395646faa7588a
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

508646 - CVE-2009-2288 nagios: remote code execution via statuswml.cgi CGI script


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/