Core Vulnerability for CVE-2016-10089
-
Fred Kroeger
- Posts: 588
- Joined: Wed Oct 19, 2011 11:36 pm
- Location: Perth, Western Australia
- Contact:
Core Vulnerability for CVE-2016-10089
The below link refers to a security vulnerability for 4.2.4 and below.
Can you advise when an update will be provided or in the meantime if there is a work-around I can implement?
https://web.nvd.nist.gov/view/vuln/deta ... 2016-10089
Thanks.... Fred
Can you advise when an update will be provided or in the meantime if there is a work-around I can implement?
https://web.nvd.nist.gov/view/vuln/deta ... 2016-10089
Thanks.... Fred
-
dwhitfield
- Former Nagios Staff
- Posts: 4583
- Joined: Wed Sep 21, 2016 10:29 am
- Location: NoLo, Minneapolis, MN
- Contact:
Re: Core Vulnerability for CVE-2016-10089
fixed in XI 5.4. Is that all you needed to know? 
-
Fred Kroeger
- Posts: 588
- Joined: Wed Oct 19, 2011 11:36 pm
- Location: Perth, Western Australia
- Contact:
Re: Core Vulnerability for CVE-2016-10089
Thanks - couldn't see a refernce to that in the Change Log.
I need to report backto the Security Team - Which release of 5.4 was the fix implemented?
I need to report backto the Security Team - Which release of 5.4 was the fix implemented?
-
dwhitfield
- Former Nagios Staff
- Posts: 4583
- Joined: Wed Sep 21, 2016 10:29 am
- Location: NoLo, Minneapolis, MN
- Contact:
Re: Core Vulnerability for CVE-2016-10089
Fix was in 5.4
Change log entry mentions a meta fix:
Please let us know if you need any more details.
Change log entry mentions a meta fix:
Nagios Core changelog at https://github.com/NagiosEnterprises/na ... /Changelog- Upgraded Nagios Core to version 4.2.4 -JO
Please let us know if you need any more details.
-
Fred Kroeger
- Posts: 588
- Joined: Wed Oct 19, 2011 11:36 pm
- Location: Perth, Western Australia
- Contact:
Re: Core Vulnerability for CVE-2016-10089
Yes I saw that entry in the change log, however the vulnerability advisory refers to to Core 4.2.4 and below.
There is no subsequent entry in the change log that states that this vulnerability has been addressed.
Sorry for the hassle.... I just need some documented proof that CVE-2016-10089 has been fixed.
There is no subsequent entry in the change log that states that this vulnerability has been addressed.
Sorry for the hassle.... I just need some documented proof that CVE-2016-10089 has been fixed.
-
dwhitfield
- Former Nagios Staff
- Posts: 4583
- Joined: Wed Sep 21, 2016 10:29 am
- Location: NoLo, Minneapolis, MN
- Contact:
Re: Core Vulnerability for CVE-2016-10089
Thank you for perseverance. We got so many questions about the things fixed in 4.2.4 that I just assumed this was one of those.
It does not appear this one has been fixed in the new releases of Core. I brought this to the attention of the Core developer. I know there is a [email protected] email address for reporting, but I am not sure if there is a way for me to view what has been reported.
It does not appear this one has been fixed in the new releases of Core. I brought this to the attention of the Core developer. I know there is a [email protected] email address for reporting, but I am not sure if there is a way for me to view what has been reported.
-
Fred Kroeger
- Posts: 588
- Joined: Wed Oct 19, 2011 11:36 pm
- Location: Perth, Western Australia
- Contact:
Re: Core Vulnerability for CVE-2016-10089
Thanks - can you keep this open and update it please when you get confirmation that it has been fixed?
-
dwhitfield
- Former Nagios Staff
- Posts: 4583
- Joined: Wed Sep 21, 2016 10:29 am
- Location: NoLo, Minneapolis, MN
- Contact:
Re: Core Vulnerability for CVE-2016-10089
For sure. I just checked the maintenance branch on github and no changes yet.
-
Fred Kroeger
- Posts: 588
- Joined: Wed Oct 19, 2011 11:36 pm
- Location: Perth, Western Australia
- Contact:
Re: Core Vulnerability for CVE-2016-10089
Was this vulnerablity addressed in the latest release of NagiosXI ?
-
dwhitfield
- Former Nagios Staff
- Posts: 4583
- Joined: Wed Sep 21, 2016 10:29 am
- Location: NoLo, Minneapolis, MN
- Contact:
Re: Core Vulnerability for CVE-2016-10089
Looks like there is no fix yet in the maint branch: https://github.com/NagiosEnterprises/na ... /Changelog
Occasionally there are fixes in XI that aren't in Core, but it does not look like this is one of them: https://assets.nagios.com/downloads/nag ... NGES-5.TXT
I filed a github issue so it doesn't slip through the cracks: https://github.com/NagiosEnterprises/na ... issues/353
Occasionally there are fixes in XI that aren't in Core, but it does not look like this is one of them: https://assets.nagios.com/downloads/nag ... NGES-5.TXT
I filed a github issue so it doesn't slip through the cracks: https://github.com/NagiosEnterprises/na ... issues/353