Debian Security Advisory
DLA-461-1 nagios3 -- LTS security update
- Date Reported:
- 07 May 2016
- Affected Packages:
- nagios3
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2014-1878.
- More information:
-
A stack-based buffer overflow in the cmd_submitf function in cgi/cmd.c in Nagios, a monitoring and management system for hosts, services and networks, allowed remote attackers to cause a denial of service (segmentation fault) via a long message to cmd.cgi.
For Debian 7
Wheezy
, this problem has been fixed in version 3.4.1-3+deb7u2.We recommend that you upgrade your nagios3 packages.