CVE-2013-7107

Publication date 15 January 2014

Last updated 24 July 2024


Ubuntu priority

Cross-site request forgery (CSRF) vulnerability in cmd.cgi in Icinga 1.8.5, 1.9.4, 1.10.2, and earlier allows remote attackers to hijack the authentication of users for unspecified commands via unspecified vectors, as demonstrated by bypassing authentication requirements for CVE-2013-7106.

Read the notes from the security team

Status

Package Ubuntu Release Status
icinga 13.10 saucy Ignored
13.04 raring Ignored
12.10 quantal Ignored
12.04 LTS precise Ignored
10.04 LTS lucid Not in release
nagios3 13.10 saucy Ignored
13.04 raring Ignored
12.10 quantal Ignored
12.04 LTS precise Ignored
10.04 LTS lucid Ignored end of life

Notes


mdeslaur

fixing this in stable releases will break compatibility with some addons and scripts, ignoring.