Contact | Site en Français               

 


 

Vulnerabilities & Threats

 
  VUPEN Security Advisories
  Linux Security Advisories

  Malware Advisories

  Security Research
  Threat Watch Blog
  Zero-Day Monitor
  Search Engine
  Mailing List & RSS
 
   

>> Fedora Security Update Fixes Nagios Cross Site Scripting Vulnerability

Title : Fedora Security Update Fixes Nagios Cross Site Scripting Vulnerability
VUPEN ID : VUPEN/ADV-2007-4128
CVE ID : CVE-2007-5624
Rated as : Low Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2007-12-10


Technical Description    Receive VUPEN Security alerts in a Text format  Receive VUPEN Security alerts in a PDF format  Receive VUPEN Security alerts in an XML format 

A vulnerability has been identified in Fedora, which could be exploited by attackers to execute arbitrary scripting code. This issue is caused by an error in Nagios. For additional information, see : VUPEN/ADV-2007-3567

Affected Products

Fedora 7

Solution

Upgrade the affected packages :

81a09c13426f60076844496abc54dfbbb84cf7eb nagios-2.10-3.fc7.ppc64.rpm
5a67dea82d753a85bd8329a0e4462308af1bfa4e nagios-devel-2.10-3.fc7.ppc64.rpm
fdcf9b005c71e13bab0b0ae15ead14a116663572 nagios-debuginfo-2.10-3.fc7.ppc64.rpm
796b3f95e7bcf124d67b070f0ebb760fac94b586 nagios-debuginfo-2.10-3.fc7.i386.rpm
7a2750b4b308fcd4e918f512dde840cbec40f575 nagios-2.10-3.fc7.i386.rpm
dbf21db3daf78190c891300e3b073c7204030549 nagios-devel-2.10-3.fc7.i386.rpm
f6c41af4c271858928caceef6147cf03c3df0947 nagios-devel-2.10-3.fc7.x86_64.rpm
c8f6a68c6dc38347553a03ea672837322a9fe772 nagios-2.10-3.fc7.x86_64.rpm
846ccdd5400f7cc834150de8965708aa31a9d6e7 nagios-debuginfo-2.10-3.fc7.x86_64.rpm
c8245be56d2ecc43ff8f69bc81dfd077cc7c8731 nagios-debuginfo-2.10-3.fc7.ppc.rpm
11f80539b413951ea1598425194294782075b920 nagios-devel-2.10-3.fc7.ppc.rpm
3fb7387e9f8277ca3e85c3f8f747df7112f24c2d nagios-2.10-3.fc7.ppc.rpm
2b7b4c15444d0ace086815e9905241fc2742d639 nagios-2.10-3.fc7.src.rpm

References

http://www.vupen.com/english/advisories/2007/4128
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00125.html

ChangeLog

2007-12-10 : Initial release

Vulnerability Management

Subscribe to VUPEN VNS and receive real-time alerts when new advisories or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form.

 

Vulnerability Alerting

Free 14-Day Trial

 
  Latest News

 

  >> 2009-07-06

     

  Microsoft Windows 0-Day
  Flaw Exploited in the Wild


  >> 2009-06-10

     

  VUPEN Security Research
  Discovered Critical Flaws
  in Adobe Acrobat and MS

  Office Word


  >> 2009-06-02

     

  VUPEN Security Research
  Discovered Critical Flaws
  in ACDSee Products


  >> 2009-05-22

     

  VUPEN Discovered Two
  Critical Vulnerabilities in
  Novell GroupWise 8 / 7

 

 

More Informations    
    








Copyright 2003-2009 © VUPEN.COM - Privacy Policy