guix-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: 01/01: gnu: Add Nagios.


From: Ludovic Courtès
Subject: Re: 01/01: gnu: Add Nagios.
Date: Sat, 31 Dec 2016 20:05:11 +0100
User-agent: Gnus/5.13 (Gnus v5.13) Emacs/25.1 (gnu/linux)

Leo Famulari <address@hidden> skribis:

> On Wed, Nov 30, 2016 at 10:31:09PM +0000, Ludovic Court�s wrote:
>> civodul pushed a commit to branch master
>> in repository guix.
>> 
>> commit d30e578a0011b05d1e7d8b3ba7ee38588eba301c
>> Author: Ludovic Courtès <address@hidden>
>> Date:   Wed Nov 30 23:26:57 2016 +0100
>> 
>>     gnu: Add Nagios.
>>     
>>     * gnu/packages/monitoring.scm: New file.
>>     * gnu/local.mk (GNU_SYSTEM_MODULES): Add it.
>
>> +    (version "4.0.8")
>> +    ;; XXX: Newer versions such as 4.2.3 bundle a copy of AngularJS.
>
> This version of Nagios includes some severe security vulnerabilities:
>
> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9566
> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9565
>
> They allow remote attackers to read and write arbitrary files (leading
> to remote code execution) or to escalate privilege to the superuser.
>
> What should we do?

Updated to 4.2.4 in 7fc2d377d16b5aefacf01e3c9105dc0344a33dbe.

Ludo’.



reply via email to

[Prev in Thread] Current Thread [Next in Thread]