Skip to content
This repository has been archived by the owner on Jan 15, 2019. It is now read-only.

[dev.icinga.com #3532] CVE-2012-6096 - history.cgi remote command execution #1201

Closed
icinga-migration opened this issue Jan 13, 2013 · 3 comments
Milestone

Comments

@icinga-migration
Copy link

This issue has been migrated from Redmine: https://dev.icinga.com/issues/3532

Created by mfriedrich on 2013-01-13 21:14:12 +00:00

Assignee: mfriedrich
Status: Resolved (closed on 2013-01-13 22:41:14 +00:00)
Target Version: 1.9
Last Update: 2014-12-08 09:28:00 +00:00 (in Redmine)

Icinga Version: 1.8.3
OS Version: any

there's a cve floating around the net with the subject "CVE-2012-6096 - Nagios history.cgi Remote Command Execution" which may affect Icinga as well, having the same code base as Nagios in this regard.

tests have unveiled, that without authorization (or by given auth credentials), this cve is valid. though, Icinga requires some more changes on that.

since there are some other bugfixes on the plate for 1.8.4, we'll port the nagios patch, after having investigated their patch for a while now. furthermore, this patch must be backported to existing 1.7.x and 1.6.x branches

Changesets

2013-01-13 21:10:10 +00:00 by (unknown) 747736d

possible fix for CVE-2012-6096 (nagios), added Icinga specific fixes

refs #3532

2013-01-13 21:17:57 +00:00 by (unknown) 7142766

possible fix for CVE-2012-6096 (nagios), added Icinga specific fixes

refs #3532

2013-01-13 21:22:12 +00:00 by (unknown) 46f5557

possible fix for CVE-2012-6096 (nagios), added Icinga specific fixes

refs #3532

Conflicts:
	cgi/cgiutils.c
	cgi/status.c

2013-01-13 21:23:29 +00:00 by (unknown) 600418e

possible fix for CVE-2012-6096 (nagios), added Icinga specific fixes

refs #3532

Conflicts:
	cgi/cgiutils.c
	cgi/status.c
@icinga-migration
Copy link
Author

Updated by mfriedrich on 2013-01-13 22:41:14 +00:00

  • Status changed from Assigned to Resolved
  • Done % changed from 0 to 100

@icinga-migration
Copy link
Author

Updated by mfriedrich on 2013-01-13 22:41:32 +00:00

https://www.icinga.org/2013/01/14/icinga-1-6-2-1-7-4-1-8-4-released/

@icinga-migration
Copy link
Author

Updated by mfriedrich on 2014-12-08 09:28:00 +00:00

  • Project changed from 19 to Core, Classic UI, IDOUtils
  • Category changed from 52 to Classic UI
  • OS Version set to any

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

1 participant