Summary
The remote host is missing an update to nagios3
announced via advisory USN-795-1.
Solution
The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 8.04 LTS:
nagios2 2.11-1ubuntu1.5
Ubuntu 8.10:
nagios3 3.0.2-1ubuntu1.2
Ubuntu 9.04:
nagios3 3.0.6-2ubuntu1.1
After a standard system upgrade you need to restart Nagios to effect the necessary changes.
https://secure1.securityspace.com/smysecure/catid.html?in=USN-795-1
Insight
It was discovered that Nagios did not properly parse certain commands submitted using the WAP web interface. An authenticated user could exploit this flaw and execute arbitrary programs on the server.
Severity
Classification
-
CVE CVE-2009-2288 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities