MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "nagios3", "binary_version": "3.5.1-1ubuntu1" }, { "binary_name": "nagios3-cgi", "binary_version": "3.5.1-1ubuntu1" }, { "binary_name": "nagios3-common", "binary_version": "3.5.1-1ubuntu1" }, { "binary_name": "nagios3-core", "binary_version": "3.5.1-1ubuntu1" }, { "binary_name": "nagios3-dbg", "binary_version": "3.5.1-1ubuntu1" }, { "binary_name": "nagios3-doc", "binary_version": "3.5.1-1ubuntu1" } ] }