CVE-2013-4214: Medium severity nagios plugins vulnerability
+++ This bug was initially created as a clone of Bug #957481 +++
Some potential issues discovered whilst auditing openstack & dependencies for tempfile vulnerabilities.
Warning: nagios-3.4.4-1.el6ost/nagios/html/rss-newsfeed.php
define('MAGPIECACHEDIR', '/tmp/magpiecache');
Magpie RSS cache dir is set to a fixed location in /tmp. The cached RSS content is then used to build html content that could be served to an end user.
Other sources
rss-newsfeed.php in Nagios Core 3.4.4, 3.5.1, and earlier, when MAGPIECACHEON is set to 1, allows local users to overwrite arbitrary files via a symlink attack on /tmp/magpiecache.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4214?
The severity of CVE-2013-4214 is considered to be high due to potential vulnerabilities in Nagios and OpenStack software versions.
How do I fix CVE-2013-4214?
To fix CVE-2013-4214, update Nagios to version 3.5.1 or later, or apply relevant patches for affected OpenStack versions.
Which versions of Nagios are affected by CVE-2013-4214?
CVE-2013-4214 affects Nagios versions up to and including 3.5.1 and specifically version 3.4.4.
Is CVE-2013-4214 related to file handling issues in Nagios?
Yes, CVE-2013-4214 is related to tempfile vulnerabilities discovered in Nagios during an audit for security issues.
Are there any workarounds for CVE-2013-4214?
There are no specific workarounds documented for CVE-2013-4214; the recommended action is to update to the latest version.