MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "3.5.1-1ubuntu1", "binary_name": "nagios3" }, { "binary_version": "3.5.1-1ubuntu1", "binary_name": "nagios3-cgi" }, { "binary_version": "3.5.1-1ubuntu1", "binary_name": "nagios3-common" }, { "binary_version": "3.5.1-1ubuntu1", "binary_name": "nagios3-core" }, { "binary_version": "3.5.1-1ubuntu1", "binary_name": "nagios3-dbg" }, { "binary_version": "3.5.1-1ubuntu1", "binary_name": "nagios3-doc" } ] }