Lucene search

K
ubuntuUbuntuUSN-1151-1
HistoryJun 15, 2011 - 12:00 a.m.

Nagios vulnerabilities

2011-06-1500:00:00
ubuntu.com
58

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.3

Confidence

High

EPSS

0.026

Percentile

90.6%

Releases

  • Ubuntu 11.04
  • Ubuntu 10.10
  • Ubuntu 10.04

Packages

  • nagios3 - A host/service/network monitoring and management system

Details

Stefan Schurtz discovered than Nagios did not properly sanitize its input
when processing certain requests, resulting in cross-site scripting (XSS)
vulnerabilities. With cross-site scripting vulnerabilities, if a user were
tricked into viewing server output during a crafted server request, a
remote attacker could exploit this to modify the contents, or steal
confidential data, within the same domain.

OSVersionArchitecturePackageVersionFilename
Ubuntu11.04noarchnagios3-cgi< 3.2.3-1ubuntu1.2UNKNOWN
Ubuntu11.04noarchnagios3< 3.2.3-1ubuntu1.2UNKNOWN
Ubuntu11.04noarchnagios3-core< 3.2.3-1ubuntu1.2UNKNOWN
Ubuntu11.04noarchnagios3-dbg< 3.2.3-1ubuntu1.2UNKNOWN
Ubuntu10.10noarchnagios3-cgi< 3.2.1-2ubuntu1.2UNKNOWN
Ubuntu10.10noarchnagios3< 3.2.1-2ubuntu1.2UNKNOWN
Ubuntu10.10noarchnagios3-core< 3.2.1-2ubuntu1.2UNKNOWN
Ubuntu10.10noarchnagios3-dbg< 3.2.1-2ubuntu1.2UNKNOWN
Ubuntu10.04noarchnagios3-cgi< 3.2.0-4ubuntu2.2UNKNOWN
Ubuntu10.04noarchnagios3< 3.2.0-4ubuntu2.2UNKNOWN
Rows per page:
1-10 of 121

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.3

Confidence

High

EPSS

0.026

Percentile

90.6%