Local Denial of Service CVE-2018-13457

Support forum for Nagios Core, Nagios Plugins, NCPA, NRPE, NSCA, NDOUtils and more. Engage with the community of users including those using the open source solutions.
Locked
hbouma
Posts: 483
Joined: Tue Feb 27, 2018 9:31 am

Local Denial of Service CVE-2018-13457

Post by hbouma »

My IT Security department is asking what the offical stance is for this CVE. We are unable to move forward with our switch to Nagios at this time due to this vulnerability.

https://nvd.nist.gov/vuln/detail/CVE-2018-13458
scottwilkerson
DevOps Engineer
Posts: 19396
Joined: Tue Nov 15, 2011 3:11 pm
Location: Nagios Enterprises
Contact:

Re: Local Denial of Service CVE-2018-13457

Post by scottwilkerson »

This is fixed in the maint branch of Nagios and is undergoing final testing
https://github.com/NagiosEnterprises/na ... tree/maint
Former Nagios employee
Creator:
Human Design Website
Get Your Human Design Chart
hbouma
Posts: 483
Joined: Tue Feb 27, 2018 9:31 am

Re: Local Denial of Service CVE-2018-13457

Post by hbouma »

So that will push it to the new version of Nagios Core. Good.

Will it be included in an upcoming version of Nagios XI?
scottwilkerson
DevOps Engineer
Posts: 19396
Joined: Tue Nov 15, 2011 3:11 pm
Location: Nagios Enterprises
Contact:

Re: Local Denial of Service CVE-2018-13457

Post by scottwilkerson »

hbouma wrote:So that will push it to the new version of Nagios Core. Good.

Will it be included in an upcoming version of Nagios XI?
yes and yes
Former Nagios employee
Creator:
Human Design Website
Get Your Human Design Chart
hbouma
Posts: 483
Joined: Tue Feb 27, 2018 9:31 am

Re: Local Denial of Service CVE-2018-13457

Post by hbouma »

Thank you. That is all I needed.
scottwilkerson
DevOps Engineer
Posts: 19396
Joined: Tue Nov 15, 2011 3:11 pm
Location: Nagios Enterprises
Contact:

Re: Local Denial of Service CVE-2018-13457

Post by scottwilkerson »

hbouma wrote:Thank you. That is all I needed.
Closing
Former Nagios employee
Creator:
Human Design Website
Get Your Human Design Chart
Locked