diff options
| author | sakib.sajal@windriver.com <sakib.sajal@windriver.com> | 2020-04-30 16:48:15 -0700 |
|---|---|---|
| committer | Bruce Ashfield <bruce.ashfield@gmail.com> | 2020-05-02 11:04:53 -0400 |
| commit | 3c4c50462cf32ff32e0a8bd2b90047d5ccd445f9 (patch) | |
| tree | 136d9768c2862f5f0c5b35e0e35c94314d2bb852 | |
| parent | 019be67a3f9e15718946902c086af1cdc65f1e9d (diff) | |
| download | meta-virtualization-3c4c50462cf32ff32e0a8bd2b90047d5ccd445f9.tar.gz | |
nagios-nrpe: Fix CVE-2020-6581
Backport fix for CVE-2020-6581
Signed-off-by: Sakib Sajal <sakib.sajal@windriver.com>
Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
| -rw-r--r-- | recipes-extended/nagios/nagios-nrpe/0001-Should-fix-235-nasty_metachars-was-not-being-returne.patch | 30 | ||||
| -rw-r--r-- | recipes-extended/nagios/nagios-nrpe_4.0.2.bb | 1 |
2 files changed, 31 insertions, 0 deletions
diff --git a/recipes-extended/nagios/nagios-nrpe/0001-Should-fix-235-nasty_metachars-was-not-being-returne.patch b/recipes-extended/nagios/nagios-nrpe/0001-Should-fix-235-nasty_metachars-was-not-being-returne.patch new file mode 100644 index 00000000..7a12e730 --- /dev/null +++ b/recipes-extended/nagios/nagios-nrpe/0001-Should-fix-235-nasty_metachars-was-not-being-returne.patch | |||
| @@ -0,0 +1,30 @@ | |||
| 1 | From 4f7dd1199f1f3f72f9197e8565da339a4a2490b7 Mon Sep 17 00:00:00 2001 | ||
| 2 | From: madlohe <swolf@nagios.com> | ||
| 3 | Date: Thu, 23 Apr 2020 15:33:18 -0500 | ||
| 4 | Subject: [PATCH] Should fix #235 (nasty_metachars was not being returned when | ||
| 5 | specified in cfg file | ||
| 6 | |||
| 7 | CVE: CVE-2020-6581 | ||
| 8 | Upstream Status: Backport [4f7dd1199f1f3f72f9197e8565da339a4a2490b7] | ||
| 9 | |||
| 10 | Signed-off-by: Sakib Sajal <sakib.sajal@windriver.com> | ||
| 11 | --- | ||
| 12 | src/nrpe.c | 2 ++ | ||
| 13 | 1 file changed, 2 insertions(+) | ||
| 14 | |||
| 15 | diff --git a/src/nrpe.c b/src/nrpe.c | ||
| 16 | index 01fbd1d..bf64963 100644 | ||
| 17 | --- a/src/nrpe.c | ||
| 18 | +++ b/src/nrpe.c | ||
| 19 | @@ -823,6 +823,8 @@ char* process_metachars(const char* input) | ||
| 20 | } | ||
| 21 | } | ||
| 22 | copy[j] = '\0'; | ||
| 23 | + | ||
| 24 | + return copy; | ||
| 25 | } | ||
| 26 | |||
| 27 | /* read in the configuration file */ | ||
| 28 | -- | ||
| 29 | 2.20.1 | ||
| 30 | |||
diff --git a/recipes-extended/nagios/nagios-nrpe_4.0.2.bb b/recipes-extended/nagios/nagios-nrpe_4.0.2.bb index c8875fcc..d9c7b159 100644 --- a/recipes-extended/nagios/nagios-nrpe_4.0.2.bb +++ b/recipes-extended/nagios/nagios-nrpe_4.0.2.bb | |||
| @@ -13,6 +13,7 @@ SRCNAME = "nrpe" | |||
| 13 | SRC_URI = "https://github.com/NagiosEnterprises/nrpe/releases/download/${SRCNAME}-${PV}/${SRCNAME}-${PV}.tar.gz \ | 13 | SRC_URI = "https://github.com/NagiosEnterprises/nrpe/releases/download/${SRCNAME}-${PV}/${SRCNAME}-${PV}.tar.gz \ |
| 14 | file://check_nrpe.cfg \ | 14 | file://check_nrpe.cfg \ |
| 15 | file://nagios-nrpe.service \ | 15 | file://nagios-nrpe.service \ |
| 16 | file://0001-Should-fix-235-nasty_metachars-was-not-being-returne.patch \ | ||
| 16 | " | 17 | " |
| 17 | 18 | ||
| 18 | SRC_URI[md5sum] = "37b9e23b3e8d75308f8b31f3b61ee8a4" | 19 | SRC_URI[md5sum] = "37b9e23b3e8d75308f8b31f3b61ee8a4" |
