Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1114841 - (CVE-2014-4702) CVE-2014-4702 nagios-plugins: check_icmp Arbitrary Option File Read
CVE-2014-4702 nagios-plugins: check_icmp Arbitrary Option File Read
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20140516,repo...
: Security
Depends On: 1098548 1098549
Blocks: 1114439
  Show dependency treegraph
 
Reported: 2014-07-01 02:44 EDT by Murray McAllister
Modified: 2018-01-30 18:45 EST (History)
17 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Murray McAllister 2014-07-01 02:44:48 EDT
Similar to the CVE-2014-4701 issue in the check_dhcp plug-in, the same flaw was found to affect check_icmp. A local attacker could obtain sensitive information by using this flaw to read parts of INI configuration files that belong to the root user.

This issue was fixed in version 2.0.2:

http://nagios-plugins.org/nagios-plugins-2-0-2-released/

References:
http://seclists.org/fulldisclosure/2014/May/74
https://bugzilla.redhat.com/show_bug.cgi?id=1098531
http://seclists.org/oss-sec/2014/q2/709
Comment 1 Murray McAllister 2014-07-01 02:47:14 EDT
Created nagios-plugins tracking bugs for this issue:

Affects: fedora-all [bug 1098548]
Affects: epel-all [bug 1098549]
Comment 2 Garth Mollett 2014-07-18 02:10:00 EDT
Statement:

This issue did not affect the versions of nagios-plugins as shipped with Red Hat Enterprise Linux OpenStack Platform.
Comment 4 Fedora Update System 2015-08-18 01:14:05 EDT
nagios-plugins-2.0.3-1.fc21 has been pushed to the Fedora 21 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 5 Fedora Update System 2015-08-18 01:22:09 EDT
nagios-plugins-2.0.3-1.fc22 has been pushed to the Fedora 22 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 6 Fedora Update System 2015-08-18 01:28:01 EDT
nagios-plugins-2.0.3-1.fc23 has been pushed to the Fedora 23 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 7 Fedora Update System 2015-08-22 15:25:08 EDT
nagios-plugins-2.0.3-1.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report.
Comment 8 Fedora Update System 2015-08-22 23:00:09 EDT
nagios-plugins-2.0.3-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.