CVE-2013-7107

NameCVE-2013-7107
DescriptionCross-site request forgery (CSRF) vulnerability in cmd.cgi in Icinga 1.8.5, 1.9.4, 1.10.2, and earlier allows remote attackers to hijack the authentication of users for unspecified commands via unspecified vectors, as demonstrated by bypassing authentication requirements for CVE-2013-7106.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-2956-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
icinga (PTS)jessie1.11.6-1fixed
stretch1.13.4-2fixed
buster1.14.2+ds-3fixed
nagios3 (PTS)jessie, jessie (lts)3.5.1.dfsg-2+deb8u1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
icingasourcewheezy1.7.1-7DSA-2956-1
icingasource(unstable)1.10.2-1low
nagios3source(unstable)(unfixed)low

Notes

[squeeze] - icinga <no-dsa> (Minor issue)
[jessie] - nagios3 <no-dsa> (Minor issue)
[squeeze] - nagios3 <no-dsa> (Minor issue)
[wheezy] - nagios3 <no-dsa> (Minor issue)
https://dev.icinga.org/issues/5346

Search for package or bug name: Reporting problems