Core Vulnerability for CVE-2016-10089

Support forum for Nagios Core, Nagios Plugins, NCPA, NRPE, NSCA, NDOUtils and more. Engage with the community of users including those using the open source solutions.
Locked
Fred Kroeger
Posts: 588
Joined: Wed Oct 19, 2011 11:36 pm
Location: Perth, Western Australia
Contact:

Core Vulnerability for CVE-2016-10089

Post by Fred Kroeger »

The below link refers to a security vulnerability for 4.2.4 and below.
Can you advise when an update will be provided or in the meantime if there is a work-around I can implement?

https://web.nvd.nist.gov/view/vuln/deta ... 2016-10089

Thanks.... Fred
dwhitfield
Former Nagios Staff
Posts: 4583
Joined: Wed Sep 21, 2016 10:29 am
Location: NoLo, Minneapolis, MN
Contact:

Re: Core Vulnerability for CVE-2016-10089

Post by dwhitfield »

fixed in XI 5.4. Is that all you needed to know? :)
Fred Kroeger
Posts: 588
Joined: Wed Oct 19, 2011 11:36 pm
Location: Perth, Western Australia
Contact:

Re: Core Vulnerability for CVE-2016-10089

Post by Fred Kroeger »

Thanks - couldn't see a refernce to that in the Change Log.
I need to report backto the Security Team - Which release of 5.4 was the fix implemented?
dwhitfield
Former Nagios Staff
Posts: 4583
Joined: Wed Sep 21, 2016 10:29 am
Location: NoLo, Minneapolis, MN
Contact:

Re: Core Vulnerability for CVE-2016-10089

Post by dwhitfield »

Fix was in 5.4

Change log entry mentions a meta fix:
- Upgraded Nagios Core to version 4.2.4 -JO
Nagios Core changelog at https://github.com/NagiosEnterprises/na ... /Changelog

Please let us know if you need any more details.
Fred Kroeger
Posts: 588
Joined: Wed Oct 19, 2011 11:36 pm
Location: Perth, Western Australia
Contact:

Re: Core Vulnerability for CVE-2016-10089

Post by Fred Kroeger »

Yes I saw that entry in the change log, however the vulnerability advisory refers to to Core 4.2.4 and below.
There is no subsequent entry in the change log that states that this vulnerability has been addressed.
Sorry for the hassle.... I just need some documented proof that CVE-2016-10089 has been fixed.
dwhitfield
Former Nagios Staff
Posts: 4583
Joined: Wed Sep 21, 2016 10:29 am
Location: NoLo, Minneapolis, MN
Contact:

Re: Core Vulnerability for CVE-2016-10089

Post by dwhitfield »

Thank you for perseverance. We got so many questions about the things fixed in 4.2.4 that I just assumed this was one of those.

It does not appear this one has been fixed in the new releases of Core. I brought this to the attention of the Core developer. I know there is a [email protected] email address for reporting, but I am not sure if there is a way for me to view what has been reported.
Fred Kroeger
Posts: 588
Joined: Wed Oct 19, 2011 11:36 pm
Location: Perth, Western Australia
Contact:

Re: Core Vulnerability for CVE-2016-10089

Post by Fred Kroeger »

Thanks - can you keep this open and update it please when you get confirmation that it has been fixed?
dwhitfield
Former Nagios Staff
Posts: 4583
Joined: Wed Sep 21, 2016 10:29 am
Location: NoLo, Minneapolis, MN
Contact:

Re: Core Vulnerability for CVE-2016-10089

Post by dwhitfield »

For sure. I just checked the maintenance branch on github and no changes yet.
Fred Kroeger
Posts: 588
Joined: Wed Oct 19, 2011 11:36 pm
Location: Perth, Western Australia
Contact:

Re: Core Vulnerability for CVE-2016-10089

Post by Fred Kroeger »

Was this vulnerablity addressed in the latest release of NagiosXI ?
dwhitfield
Former Nagios Staff
Posts: 4583
Joined: Wed Sep 21, 2016 10:29 am
Location: NoLo, Minneapolis, MN
Contact:

Re: Core Vulnerability for CVE-2016-10089

Post by dwhitfield »

Looks like there is no fix yet in the maint branch: https://github.com/NagiosEnterprises/na ... /Changelog

Occasionally there are fixes in XI that aren't in Core, but it does not look like this is one of them: https://assets.nagios.com/downloads/nag ... NGES-5.TXT

I filed a github issue so it doesn't slip through the cracks: https://github.com/NagiosEnterprises/na ... issues/353
Locked