CVE-2016-9565: Command Injection

Published Dec 15, 2016
·
Updated

MagpieRSS, a component for handling RSS news feeds in Nagios Core control panel / front-end, was found vulnerable to command injection due to insufficient neutralization of special elements in function httpsrequest().

The vulnerability could potentially enable remote unauthenticated attackers who managed to impersonate the feed server (via DNS poisoning, domain hijacking, ARP spoofing etc.), to provide a malicious response that injects parameters to curl command used by the affected RSS client class and effectively read/write arbitrary files on the vulnerable Nagios server. This could lead to Remote Code Execution in the context of www-data/nagios user on default Nagios installs that follow the official setup guidelines.

This issue is due to incomplete fix of CVE-2008-4796.

External References:

https://legalhackers.com/advisories/Nagios-Exploit-Command-Injection-CVE-2016-9565-2008-4796.html

Other sources

MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.

MITRE

Affected Software

2 affected componentsFixes available
redhat/nagios<4.2.2
4.2.2
Nagios Nagios<=4.2.1

Event History

Dec 15, 2016
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2016-9565?

CVE-2016-9565 is considered a medium severity vulnerability due to its potential for file read or write access by remote attackers.

2

How do I fix CVE-2016-9565?

To mitigate CVE-2016-9565, upgrade Nagios Core to version 4.2.2 or later.

3

What impacts does CVE-2016-9565 have on Nagios Core?

CVE-2016-9565 could allow remote attackers to read or manipulate arbitrary files through a crafted RSS feed response.

4

Which versions of Nagios are affected by CVE-2016-9565?

CVE-2016-9565 affects Nagios Core versions prior to 4.2.2, including versions up to 4.2.1.

5

Why does CVE-2016-9565 exist?

CVE-2016-9565 exists due to an incomplete fix for the earlier vulnerability CVE-2008-4796.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203