First published: Thu Dec 15 2016(Updated: )
MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/nagios | <4.2.2 | 4.2.2 |
Nagios Plugins | <=4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9565 is considered a medium severity vulnerability due to its potential for file read or write access by remote attackers.
To mitigate CVE-2016-9565, upgrade Nagios Core to version 4.2.2 or later.
CVE-2016-9565 could allow remote attackers to read or manipulate arbitrary files through a crafted RSS feed response.
CVE-2016-9565 affects Nagios Core versions prior to 4.2.2, including versions up to 4.2.1.
CVE-2016-9565 exists due to an incomplete fix for the earlier vulnerability CVE-2008-4796.