Security fixes completed

Andreas Ericsson ae at op5.se
Fri Nov 7 13:49:49 CET 2008


Ahoy all.

A slightly fixed version of the anti-CSRF fixes just passed our QA
team. We'll be packaging this patched version of Nagios 3.0.5 and
ship to our customers later today. The patched version is available
for download at http://www.op5.se/src/nagios-3.0.5p1.tar.gz
3.0.5p1 incorporates the patches sent by Badri Pillai (fixing the
service-comment issue reported by Richard Savage), as well as a
fix for the problem reported by Olivier Beytrison. The latter was
originally fixed by Hendrik Bäcker, but I made some minor mods to
Hendrik's original patch.

I'm hoping Ethan will pick up the patches later today and make a
proper release through the official channels, even though 3.0.5
got out just recently. Community testing will ofcourse make the
release process smoother for Ethan (hint, hint).

Big thanks to Tim Starling in particular for discovering the base
issues and reporting them discreetly.

As usual, please send any bug-reports to nagios-devel at . Thanks.

-- 
Andreas Ericsson                   andreas.ericsson at op5.se
OP5 AB                             www.op5.se
Tel: +46 8-230225                  Fax: +46 8-230231

-------------------------------------------------------------------------
This SF.Net email is sponsored by the Moblin Your Move Developer's challenge
Build the coolest Linux based applications with Moblin SDK & win great prizes
Grand prize is a trip for two to an Open Source event anywhere in the world
http://moblin-contest.org/redirect.php?banner_id=100&url=/




More information about the Developers mailing list