First published: Tue Apr 30 2013(Updated: )
+++ This bug was initially created as a clone of <a class="bz_bug_link bz_secure " title="" href="show_bug.cgi?id=957481">Bug #957481</a> +++ Some potential issues discovered whilst auditing openstack & dependencies for tempfile vulnerabilities. Warning: nagios-3.4.4-1.el6ost/nagios/html/rss-newsfeed.php define('MAGPIE_CACHE_DIR', '/tmp/magpie_cache'); Magpie RSS cache dir is set to a fixed location in /tmp. The cached RSS content is then used to build html content that could be served to an end user.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Plugins | <=3.5.1 | |
Nagios Plugins | =3.4.4 | |
Red Hat OpenStack for IBM Power | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-4214 is considered to be high due to potential vulnerabilities in Nagios and OpenStack software versions.
To fix CVE-2013-4214, update Nagios to version 3.5.1 or later, or apply relevant patches for affected OpenStack versions.
CVE-2013-4214 affects Nagios versions up to and including 3.5.1 and specifically version 3.4.4.
Yes, CVE-2013-4214 is related to tempfile vulnerabilities discovered in Nagios during an audit for security issues.
There are no specific workarounds documented for CVE-2013-4214; the recommended action is to update to the latest version.