Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 957482 - (CVE-2013-4215) CVE-2013-4215 Nagios plugins: IPXPING_COMMAND uses fixed location in /tmp
CVE-2013-4215 Nagios plugins: IPXPING_COMMAND uses fixed location in /tmp
Status: CLOSED NOTABUG
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All All
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20130807,repor...
: Security
Depends On: 994767 994769 994781
Blocks: 958515
  Show dependency treegraph
 
Reported: 2013-04-28 07:37 EDT by Grant Murphy
Modified: 2015-08-19 05:20 EDT (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2014-03-06 21:18:07 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Grant Murphy 2013-04-28 07:37:42 EDT
Found during an audit of openstack and all its dependencies.


Error: nagios-plugins-1.4.16-6.el6ost/nagios-plugins-1.4.16/contrib/check_ipxping.c

    #define IPXPING_COMMAND "/tmp/ipxping/ipxping"

    The IPXPING_COMMAND is used to build command line that is executed 
    later on using execv. As this is a predictable location in a public area
    a local attacker may place their own file in that location or symlink to   
    another command. AFAICT little or no checks are made about the file 
    permissions or ownership.
Comment 2 Kurt Seifried 2013-04-30 01:36:43 EDT
Confirmed in latest upstream nagios-plugins-1.4.16-80-g08f5
Comment 3 Kurt Seifried 2013-04-30 15:22:29 EDT
This issue has been reported upstream: http://tracker.nagios.org/view.php?id=451
Comment 4 Kurt Seifried 2013-08-07 21:49:37 EDT
Created nagios-plugins tracking bugs for this issue:

Affects: fedora-all [bug 994781]
Comment 7 Martin Prpič 2013-11-14 12:03:21 EST
Acknowledgements:

This issue was discovered by Grant Murphy of the Red Hat Product Security Team.

Note You need to log in before you can comment on or make changes to this bug.