MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.
{
"binaries": [
{
"binary_version": "3.5.1-1ubuntu1",
"binary_name": "nagios3"
},
{
"binary_version": "3.5.1-1ubuntu1",
"binary_name": "nagios3-cgi"
},
{
"binary_version": "3.5.1-1ubuntu1",
"binary_name": "nagios3-common"
},
{
"binary_version": "3.5.1-1ubuntu1",
"binary_name": "nagios3-core"
},
{
"binary_version": "3.5.1-1ubuntu1",
"binary_name": "nagios3-dbg"
},
{
"binary_version": "3.5.1-1ubuntu1",
"binary_name": "nagios3-doc"
}
],
"availability": "No subscription required"
}