From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) by finch.gentoo.org (Postfix) with ESMTP id 3C7221389E2 for ; Sat, 13 Dec 2014 18:59:28 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 6D366E0DEA; Sat, 13 Dec 2014 18:59:25 +0000 (UTC) Received: from smtp.gentoo.org (smtp.gentoo.org [140.211.166.183]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id 0E686E0DEA for ; Sat, 13 Dec 2014 18:59:25 +0000 (UTC) Received: from oystercatcher.gentoo.org (oystercatcher.gentoo.org [148.251.78.52]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by smtp.gentoo.org (Postfix) with ESMTPS id 482C93405CA for ; Sat, 13 Dec 2014 18:59:24 +0000 (UTC) Received: by oystercatcher.gentoo.org (Postfix, from userid 2316) id F2DA2C58F; Sat, 13 Dec 2014 18:59:22 +0000 (UTC) From: "Sean Amoss (ackle)" To: gentoo-commits@lists.gentoo.org Reply-To: gentoo-dev@lists.gentoo.org, ackle@gentoo.org Subject: [gentoo-commits] gentoo commit in xml/htdocs/security/en/glsa: glsa-201412-23.xml X-VCS-Repository: gentoo X-VCS-Files: glsa-201412-23.xml X-VCS-Directories: xml/htdocs/security/en/glsa X-VCS-Committer: ackle X-VCS-Committer-Name: Sean Amoss Content-Type: text/plain; charset=utf8 Content-Transfer-Encoding: 8bit Message-Id: <20141213185922.F2DA2C58F@oystercatcher.gentoo.org> Date: Sat, 13 Dec 2014 18:59:22 +0000 (UTC) Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-commits@lists.gentoo.org X-Archives-Salt: 05426288-a80c-40cf-a9eb-c37224fe0512 X-Archives-Hash: 7d809227aa70c45a8cdc1d0f08a92e7b ackle 14/12/13 18:59:22 Added: glsa-201412-23.xml Log: GLSA 201412-23 Revision Changes Path 1.1 xml/htdocs/security/en/glsa/glsa-201412-23.xml file : http://sources.gentoo.org/viewvc.cgi/gentoo/xml/htdocs/security/en/glsa/glsa-201412-23.xml?rev=1.1&view=markup plain: http://sources.gentoo.org/viewvc.cgi/gentoo/xml/htdocs/security/en/glsa/glsa-201412-23.xml?rev=1.1&content-type=text/plain Index: glsa-201412-23.xml =================================================================== Nagios: Multiple vulnerabilities Multiple vulnerabilities have been found in Nagios, the worst of which may allow remote code execution. nagios-core December 13, 2014 December 13, 2014: 1 447802 495132 501200 remote 3.5.1 3.5.1

Nagios is an open source host, service and network monitoring program.

Multiple vulnerabilities have been discovered in Nagios. Please review the CVE identifiers referenced below for details.

A remote attacker may be able to execute arbitrary code, cause a Denial of Service condition, or obtain sensitive information.

There is no known workaround at this time.

All Nagios users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-analyzer/nagios-core-3.5.1"
CVE-2012-6096 CVE-2013-7108 CVE-2013-7205 K_F ackle