Back

CRITICAL

nagios: Command injection via curl in MagpieRSS

Published Dec 15, 2016

Description

MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.

Affected products

Remediation

Red Hat mitigation

#!/bin/bash mv /usr/share/nagios/html/includes/rss /usr/share/nagios/html/includes/rss.disarmed mv /usr/share/nagios/html/rss-corefeed.php /usr/share/nagios/html/rss-corefeed.php.disarmed mv /usr/share/nagios/html/rss-newsfeed.php /usr/share/nagios/html/rss-newsfeed.php.disarmed This should disable rss from nagios installation and stop affected php code from being executed. Only downside to this would be news widget wont fetch any data from nagios.org rss feeds.

Metrics

Weaknesses (2)

References (20)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 15, 2016
Updated Aug 6, 2024
Reserved Nov 22, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 13, 2016