From mboxrd@z Thu Jan 1 00:00:00 1970 From: ludo@gnu.org (Ludovic =?utf-8?Q?Court=C3=A8s?=) Subject: Re: 01/01: gnu: Add Nagios. Date: Sat, 31 Dec 2016 20:05:11 +0100 Message-ID: <874m1j3ons.fsf@gnu.org> References: <20161130223109.19603.88396@vcs.savannah.gnu.org> <20161130223109.CCC082201C1@vcs.savannah.gnu.org> <20161230195216.GA9049@jasmine> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:36934) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cNOxx-0003SH-Lz for guix-devel@gnu.org; Sat, 31 Dec 2016 14:05:18 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cNOxt-0006kT-Vx for guix-devel@gnu.org; Sat, 31 Dec 2016 14:05:17 -0500 In-Reply-To: <20161230195216.GA9049@jasmine> (Leo Famulari's message of "Fri, 30 Dec 2016 14:52:16 -0500") List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Leo Famulari Cc: guix-devel@gnu.org Leo Famulari skribis: > On Wed, Nov 30, 2016 at 10:31:09PM +0000, Ludovic Court=EF=BF=BDs wrote: >> civodul pushed a commit to branch master >> in repository guix. >>=20 >> commit d30e578a0011b05d1e7d8b3ba7ee38588eba301c >> Author: Ludovic Court=C3=A8s >> Date: Wed Nov 30 23:26:57 2016 +0100 >>=20 >> gnu: Add Nagios. >>=20=20=20=20=20 >> * gnu/packages/monitoring.scm: New file. >> * gnu/local.mk (GNU_SYSTEM_MODULES): Add it. > >> + (version "4.0.8") >> + ;; XXX: Newer versions such as 4.2.3 bundle a copy of AngularJS. > > This version of Nagios includes some severe security vulnerabilities: > > https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2016-9566 > https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2016-9565 > > They allow remote attackers to read and write arbitrary files (leading > to remote code execution) or to escalate privilege to the superuser. > > What should we do? Updated to 4.2.4 in 7fc2d377d16b5aefacf01e3c9105dc0344a33dbe. Ludo=E2=80=99.