CVE-2013-1362
Publication date 9 July 2013
Last updated 24 July 2024
Ubuntu priority
Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.
Status
Package | Ubuntu Release | Status |
---|---|---|
nagios-nrpe | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
Notes
jdstrand
This is a problem but requires 'dont_blame_nrpe' to be set in /etc/nagios/nrpe.cfg. This is set to '0' in Ubuntu and there are significant warnings in /etc/nagios/nrpe.cfg about the security risks of enabling external command arguments.