https://bugzilla.wikimedia.org/show_bug.cgi?id=60112
Faidon Liambotis <[email protected]> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |[email protected] --- Comment #8 from Faidon Liambotis <[email protected]> --- Yes, there are security issues with Icinga that forced us to lock it down temporarily back in December 12th. These are CVE-2013-7106, CVE-2013-7107 & CVE-2013-7108. They are still unfixed in Ubuntu precise (LTS); Icinga is in the universe section, so the Ubuntu security team deals with them on a "best effort" basis (i.e. they might not even update it, at all). The vulnerability status per Ubuntu distribution can be tracked at: http://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-7106.html http://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-7107.html http://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-7108.html respectively. Note how they decided to ignore the first one (a CSRF), which shows IMHO a poor judgement from their part. I don't think we can take the time to do a major Icinga version upgrade right now, nor to backport the fixes ourselves. Our current strategy is "wait for Ubuntu", but if anyone wants to help the backporting process (and optionally engage with the Ubuntu security team so others can benefit from that) that'd be awesome. -- You are receiving this mail because: You are the assignee for the bug. You are on the CC list for the bug. _______________________________________________ Wikibugs-l mailing list [email protected] https://lists.wikimedia.org/mailman/listinfo/wikibugs-l
