Bug 957482 (CVE-2013-4215)

Summary: CVE-2013-4215 Nagios plugins: IPXPING_COMMAND uses fixed location in /tmp
Product: [Other] Security Response Reporter: Grant Murphy <gmurphy>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: gmollett, jkt, mjc, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: All   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-03-07 02:18:07 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 994767, 994769, 994781    
Bug Blocks: 958515    

Description Grant Murphy 2013-04-28 11:37:42 UTC
Found during an audit of openstack and all its dependencies.


Error: nagios-plugins-1.4.16-6.el6ost/nagios-plugins-1.4.16/contrib/check_ipxping.c

    #define IPXPING_COMMAND "/tmp/ipxping/ipxping"

    The IPXPING_COMMAND is used to build command line that is executed 
    later on using execv. As this is a predictable location in a public area
    a local attacker may place their own file in that location or symlink to   
    another command. AFAICT little or no checks are made about the file 
    permissions or ownership.

Comment 2 Kurt Seifried 2013-04-30 05:36:43 UTC
Confirmed in latest upstream nagios-plugins-1.4.16-80-g08f5

Comment 3 Kurt Seifried 2013-04-30 19:22:29 UTC
This issue has been reported upstream: http://tracker.nagios.org/view.php?id=451

Comment 4 Kurt Seifried 2013-08-08 01:49:37 UTC
Created nagios-plugins tracking bugs for this issue:

Affects: fedora-all [bug 994781]

Comment 7 Martin Prpič 2013-11-14 17:03:21 UTC
Acknowledgements:

This issue was discovered by Grant Murphy of the Red Hat Product Security Team.