_______________________________________________________________________
Package : nagios
Date : August 1, 2009
Affected: Corporate 4.0, Enterprise Server 5.0
_______________________________________________________________________
Problem Description:
A vulnerability has been found and corrected in nagios:
statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute
arbitrary commands via shell metacharacters in the (1) ping or (2)
Traceroute parameters (CVE-2009-2288).
This update provides nagios 3.1.2, which is not vulnerable to this
issue.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-2288
_______________________________________________________________________