[SECURITY] Fedora 20 Update: check-mk-1.2.4p5-1.fc20

updates at fedoraproject.org updates at fedoraproject.org
Sat Sep 27 10:01:37 UTC 2014


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2014-10972
2014-09-19 09:02:19
--------------------------------------------------------------------------------

Name        : check-mk
Product     : Fedora 20
Version     : 1.2.4p5
Release     : 1.fc20
URL         : http://mathias-kettner.de/check_mk
Summary     : A new general purpose Nagios-plugin for retrieving data
Description :
check-mk is a general purpose Nagios-plugin for retrieving data. It adopts a
new approach for collecting data from operating systems and network components.
It obsoletes NRPE, check_by_ssh, NSClient, and check_snmp and it has many
benefits, the most important are a significant reduction of CPU usage on
the Nagios host and an automatic inventory of items to be checked on hosts.

--------------------------------------------------------------------------------
Update Information:

New upstream release providing many security fixes.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Sep 17 2014 Andrea Veri <averi at fedoraproject.org> - 1.2.4p5-1
- New upstream release. Fixes CVEs:
  - CVE-2014-5338 
  - CVE-2014-5339
  - CVE-2014-5340 (BZ: #1132337, #1132339, #1132341)
- Stop shipping the j4p_performance plugin as it's deprecated. (BZ: #1133068)
- Turn Wato_Legacy_Eval as True as we want to prevent breakages
  between machines running different Python and/or check-mk releases.
  This is necessary after the 'ast' move from 'pickle' (that was
  generating a insecure API call), however the 'ast' module is still
  not available for RHEL / CentOS 5 machines. The patch is there to 
  avoid miscommunications between different distribution releases. More
  information is available at:
  http://mathias-kettner.com/check_mk_werks.php?werk_id=984.
* Sat Aug 16 2014 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.2.4p2-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild
* Sat Jun  7 2014 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.2.4p2-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
* Tue May 27 2014 Andrea Veri <averi at fedoraproject.org> - 1.2.4p2-2
- Install the mk-job binary on /usr/bin.
- Make sure the proper permissions are given to /var/lib/check_mk_agent/job
  to prevent any hard or symlink to be created by a normal user and pointing
  to any file on the filesystem exposing it on the check-mk-agent output being
  run as root. Fixes BZ #1101669.
* Mon Apr 14 2014 Andrea Veri <averi at fedoraproject.org> - 1.2.4p2-1
- New upstream release.
* Wed Apr  2 2014 Andrea Veri <averi at fedoraproject.org> - 1.2.4p1-1
- New upstream release. Fixes the missing two CVEs that were still
  left unfixed on 1.2.4:
  - CVE-2014-2330
  - CVE-2014-2331
* Tue Mar 25 2014 Andrea Veri <averi at fedoraproject.org> - 1.2.4-1
- New upstream release. Fixes the following CVEs:
  - CVE-2014-2329
  - CVE-2014-2332
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1132337 - CVE-2014-5338 CVE-2014-5339 CVE-2014-5340 check-mk: multiple flaws fixed in versions 1.2.4p4 and 1.2.5i4
        https://bugzilla.redhat.com/show_bug.cgi?id=1132337
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use
su -c 'yum update check-mk' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list