Update Info

openSUSE-2021-786


This Nagios upgrade sums up multiple security fixes and other important


Type: recommended
Severity: low
Issued: 2021-05-24
Description:
This Nagios upgrade sums up multiple security fixes and other important
changes.

Security issues fixed in this upgrade:
* bsc#1172794 / CVE-2020-13977: Fixed postauth vulnerabilities in 
                histogram.js, map.js, trends.js
* bsc#989759 / CVE-2016-6209 : The "corewindow" parameter has been 
               disabled by default
* bsc#1014637 / CVE-2016-9566 : Fixed another root privilege escalation
* bsc#1182398 : nagios_upgrade.sh writing to log file in user controlled
                directory

Additional fixes:
* bsc#1003362 : new nagios-exec-start-post script
* Fixed Map display in Internet Explorer 11 
* Fixed duplicate properties appearing in statusjson.cgi
* Fixed build process when using GCC 10
* Fixed HARD OK states triggering on the maximum check attempt

~

              

References


No references

Packages


  • nagios-4.4.6-bp151.4.6.1