Bugzilla – Bug 885205
VUL-0: CVE-2014-4701: nagios-plugins: check_dhcp Arbitrary Option File
Last modified: 2016-09-08 20:24:06 UTC
CVE-2014-4701 It was reported that check_dhcp plugin allow local unprivileged user to read parts of INI config files belonging to root on a local system. It could allow an attacker to obtain sensitive information like passwords that should only be accessible by root user. The vulnerability is due to check_dhcp plugin having Root SUID permissions and inappropriate access control when reading user provided config file (through --extra-opts= option). As stated in nagios-plugins-README.SuSE-check_dhcpm SUSE doesn't set the setuid bit as default. Therefore we aren't affected. References: https://bugzilla.redhat.com/show_bug.cgi?id=1098531 http://seclists.org/fulldisclosure/2014/May/74
bugbot adjusting priority
@Martin: as I'm on vacation, can you please take a look?
Affected packages: SLE-11-SP3: nagios-plugins SLE-11-SP3-PRODUCTS: nagios-plugins SLE-11-SP3-UPTU: nagios-plugins
SUSE-SU-2014:1352-1: An update that fixes two vulnerabilities is now available. Category: security (low) Bug References: 885205,885207 CVE References: CVE-2014-4701,CVE-2014-4702 Sources used: SUSE Linux Enterprise Server 11 SP3 for VMware (src): nagios-plugins-1.4.16-0.13.1 SUSE Linux Enterprise Server 11 SP3 (src): nagios-plugins-1.4.16-0.13.1
released