Debian Linux Security Advisory 2956-1 - Multiple security issues have been found in the Icinga host and network monitoring system (buffer overflows, cross-site request forgery, off-by ones) which could result in the execution of arbitrary code, denial of service or session hijacking.
d0f8df2fd956542b4826e59cbfdb1a5a6db0d8e28e9911aee72085b6d64e1677
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2956-1 security@debian.org
http://www.debian.org/security/ Moritz Muehlenhoff
June 11, 2014 http://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : icinga
CVE ID : CVE-2013-7106 CVE-2013-7107 CVE-2013-7108 CVE-2014-1878
CVE-2014-2386
Multiple security issues have been found in the Icinga host and network
monitoring system (buffer overflows, cross-site request forgery, off-by
ones) which could result in the execution of arbitrary code, denial of
service or session hijacking.
For the stable distribution (wheezy), these problems have been fixed in
version 1.7.1-7.
For the testing distribution (jessie), these problems have been fixed in
version 1.11.0-1.
For the unstable distribution (sid), these problems have been fixed in
version 1.11.0-1.
We recommend that you upgrade your icinga packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBAgAGBQJTmGiJAAoJEBDCk7bDfE42ht8QALgnGvSkYNUNH1hGAkLs5k8U
Uaclxk+kZl/m4sx1w1si/iF/XWMmq1+A3ptsByMXSq2dyrtqBP6Y9aJX0UU0Yyep
FvMP1XjFY+ooVVv0Yhd5nagtCreIVj/Q/bhgIxOV6b55BJaCiuOueFpRRNVX17IL
pg04TDgeKmzC3Rk4FK64fvWWoj99UnQu3D2QqToeeQfArkj+6jUGCvmcPi0c95wd
ecVZxmPaFdLkzzjLTDMN+vR4v4d5EtvGi1sLvind5ceuhzh8OMfv+j2H1Omv/w+P
Fz+vMwS6iUaOpVDo4e2uNMIR2Aa/pbGXDEC0kXj2eEdgOrh+2tSgeHNQ6sDcpKbW
rMl2iMJC930WI4u6t0thLYTYpul53gAKpQzeK4kT/24HdpPCknqxn0pbTnMEXfZC
pJri0jvZtoWpMpmUXLIhpTKHreR6/v7Fz17ZshlUuJfi11e6l6y5vEFZko/5KZxD
qEtfD3OeQhKO7Y55gsCf3r7SEDLSNDbfYqYn2Qv4b0QDPYjlZNZLXr2ldzHF7D2h
q0ysFko6vOcgneNPCvd8joil7vgZGLSRIpgYEB9G2uBIgEaCV0/n6v5pJ5E2dyBu
336ggdK9sojNvor7yzKKNs/uApD0nhR6vJS46JSVAVijIUmoLTepgEbPzdn/kGKa
1MoybG+77CBL9visVFUF
=155r
-----END PGP SIGNATURE-----