[Pkg-nagios-devel] Bug#701227: nagios-nrpe: CVE-2013-1362: allows the passing of $() as command arguments to execute shell commands

Salvatore Bonaccorso carnil at debian.org
Sat Feb 23 10:05:49 UTC 2013


On Sat, Feb 23, 2013 at 08:33:20AM +0100, Salvatore Bonaccorso wrote:
> In the debian package we have explicitly --enable-command-args so the
> Debian packages looks affected.

But needs to be explicitly enabled in /etc/nagios/nrpe.cfg, should be
added to the above.

Regards,
Salvatore



More information about the Pkg-nagios-devel mailing list