GLSA-200605-07 : Nagios: Buffer overflow
High Nessus Plugin ID 21349
SynopsisThe remote Gentoo host is missing one or more security-related patches.
DescriptionThe remote host is affected by the vulnerability described in GLSA-200605-07 (Nagios: Buffer overflow)
Sebastian Krahmer of the SuSE security team discovered a buffer overflow vulnerability in the handling of a negative HTTP Content-Length header.
A buffer overflow in Nagios CGI scripts under certain web servers allows remote attackers to execute arbitrary code via a negative content length HTTP header.
There is no known workaround at this time.
SolutionAll Nagios users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=net-analyzer/nagios-core-1.4.1'