Nagios: Multiple vulnerabilities Multiple vulnerabilities have been found in Nagios, the worst of which could lead to privilege escalation. nagios 2017-02-21 2017-02-21 595194 598104 600864 602216 local, remote 4.2.4 4.2.4

Nagios is an open source host, service and network monitoring program.

Multiple vulnerabilities have been discovered in Nagios. Please review the CVE identifiers referenced below for details.

A local attacker, who either is already Nagios’s system user or belongs to Nagios’s group, could potentially escalate privileges.

In addition, a remote attacker could read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server.

There is no known workaround at this time.

All Nagios users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-analyzer/nagios-core-4.2.4"
CVE-2008-4796 CVE-2008-7313 CVE-2016-8641 CVE-2016-9565 CVE-2016-9566 whissi b-man