Bug#745272: [Pkg-nagios-devel] Bug#745272: NRPE - Nagios Remote Plugin Executor <= 2.15 Remote CommandExecution, POC released

2014-04-19 Thread Markus Manzke
hi alex There is a good reason we don't recommend using arguments... Alex yes, i know; thats why a similar bug is unfixed in squeeze for a year or so now, although reported regards, markus -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubsc

Bug#745272: NRPE - Nagios Remote Plugin Executor <= 2.15 Remote CommandExecution, POC released

2014-04-19 Thread Markus Manzke
Package: nagios-nrpe-server Severity: critical Tags: security NRPE fails to check input when a newline-character is issued POC has been released and works on debian 7, no CVE assigned yet http://seclists.org/fulldisclosure/2014/Apr/240 http://seclists.org/oss-sec/2014/q2/136 -- System Informa

Bug#656871: [pkg-lighttpd] Bug#656871: stop any other running httpd before

2012-02-03 Thread Markus Manzke
please make stopping of another running http-process optional; i have a lot of cases where i want to install lighttpd additional to an existing apache-httpd, using a different / unprivileged port. regards, Markus Manzke / mare system -- To UNSUBSCRIBE, email to debian-bugs-dist-requ