MGASA-2020-0247

Source
https://advisories.mageia.org/MGASA-2020-0247.html
Import Source
https://advisories.mageia.org/MGASA-2020-0247.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0247
Related
Published
2020-06-10T22:26:12Z
Modified
2020-06-10T23:17:53Z
Summary
Updated nrpe packages fix security vulnerability
Details

Updated nrpe packages fix security vulnerabilities:

Nagios NRPE 3.2.1 has Insufficient Filtering because, for example, nasty_metachars interprets \n as the character \ and the character n (not as the \n newline sequence). This can cause command injection (CVE-2020-6581).

Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call (CVE-2020-6582).

References
Credits

Affected packages

Mageia:7 / nrpe

Package

Name
nrpe
Purl
pkg:rpm/mageia/nrpe?arch=source&distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.2.1-3.2.mga7

Ecosystem specific

{
    "section": "core"
}