{"id":"openSUSE-SU-2020:0517-1","summary":"Security update for nagios","details":"This update for nagios to version 4.4.5 fixes the following issues:\n\n- CVE-2019-3698: Symbolic link following vulnerability in the cronjob allows \n  local attackers to cause cause DoS or potentially escalate privileges. (boo#1156309)\n- CVE-2018-18245: Fixed XSS vulnerability in Alert Summary report (boo#1119832)\n- CVE-2018-13441, CVE-2018-13458, CVE-2018-13457: Fixed a few denial of service \n  vulnerabilities caused by null pointer dereference (boo#1101293, boo#1101289, boo#1101290).\n\nThis update was imported from the openSUSE:Leap:15.1:Update update project.","modified":"2026-03-11T07:32:26.099562Z","published":"2020-04-14T16:11:03Z","related":["CVE-2018-13441","CVE-2018-13457","CVE-2018-13458","CVE-2018-18245","CVE-2019-3698"],"upstream":["CVE-2018-13441","CVE-2018-13457","CVE-2018-13458","CVE-2018-18245","CVE-2019-3698"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/G5J75GK25DTTK4SXS4VCSBZ3KBQ2JPAU/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1028975"},{"type":"REPORT","url":"https://bugzilla.suse.com/1119832"},{"type":"REPORT","url":"https://bugzilla.suse.com/1156309"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-13441"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-13457"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-13458"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-18245"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-3698"}],"affected":[{"package":{"name":"nagios","ecosystem":"SUSE:Package Hub 15 SP1","purl":"pkg:rpm/suse/nagios&distro=SUSE%20Package%20Hub%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.4.5-bp151.4.3.1"}]}],"ecosystem_specific":{"binaries":[{"nagios-contrib":"4.4.5-bp151.4.3.1","nagios-devel":"4.4.5-bp151.4.3.1","nagios-theme-exfoliation":"4.4.5-bp151.4.3.1","nagios-www-dch":"4.4.5-bp151.4.3.1","nagios-www":"4.4.5-bp151.4.3.1","nagios":"4.4.5-bp151.4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0517-1.json"}}],"schema_version":"1.7.5"}