[Pkg-nagios-devel] Bug#745272: Bug#745272: Bug#745272: NRPE - Nagios Remote Plugin Executor <= 2.15 Remote CommandExecution, POC released

Alexander Wirt formorer at debian.org
Thu Apr 24 12:22:43 UTC 2014


On Sun, 20 Apr 2014, Markus Manzke wrote:

> 
> 
> hi alex
> 
> >There is a good reason we don't recommend using arguments...
> >
> >Alex
> 
> yes, i know; thats why a similar bug is unfixed in squeeze
> for a year or so now, although reported
just a followup:

http://seclists.org/oss-sec/2014/q2/155

upstream says that this is "expected behaviour".

If you ask me, we should just patch that "feature" out and ship nrpe without
macro expansion.

Alex



More information about the Pkg-nagios-devel mailing list