PHP vulnerabilities found during scan of NagiosXi
Posted: Fri Nov 16, 2012 12:34 pm
CENTOS 5.8 64 bit
Manual Install of XI (Nagios XI 2012R1.2) evaluation
No special configuration. Base OS install is stripped down as much as possible. The original base install does not have php on it.
Nagios installs and seems to work fine. When we run a vulnerability scan on the installation, the scan indicates that there are 24 php vulnerabilities in the versions of php (5.1.6-x) installed by Nagiosxi. We updated php to 5.1.6-39 (newest 5.1 version available on Centos 5.8). A rescan indicated the same vulnerabilities still exist.
Nagiosxi on Centos 6.3 uses php 5.3.3-x with far fewer vulnerabilities identified.
My question (finally) is can we upgrade php on Centos 5.8 to 5.3 (5.3.3-13.el5_8.x86_64.rpm) without breaking Nagiosxi functionality?
Manual Install of XI (Nagios XI 2012R1.2) evaluation
No special configuration. Base OS install is stripped down as much as possible. The original base install does not have php on it.
Nagios installs and seems to work fine. When we run a vulnerability scan on the installation, the scan indicates that there are 24 php vulnerabilities in the versions of php (5.1.6-x) installed by Nagiosxi. We updated php to 5.1.6-39 (newest 5.1 version available on Centos 5.8). A rescan indicated the same vulnerabilities still exist.
Nagiosxi on Centos 6.3 uses php 5.3.3-x with far fewer vulnerabilities identified.
My question (finally) is can we upgrade php on Centos 5.8 to 5.3 (5.3.3-13.el5_8.x86_64.rpm) without breaking Nagiosxi functionality?