stable

monitorix-3.8.1-1.fc23

FEDORA-2015-b6b8582f4e created by mikaku 9 years ago for Fedora 23

This is a maintenance release that mainly fixes a Document Object Model (DOM)-based cross-site scripting (XSS) vulnerability in the monitorix.cgi file. Such vulnerability is by injection a JS code in the when parameter of the URL shown after generating the graphs. Additionally, a potential denial of service (DoS) issue was discovered in the same when parameter of the URL which could lead in the creation of an enormous amount of .png files in the imgs directory of the server.

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2015-b6b8582f4e

This update has been submitted for testing by mikaku.

9 years ago

This update has been pushed to testing.

9 years ago

This update has been submitted for stable by bodhi.

9 years ago
User Icon cicku provided feedback 9 years ago
karma
BZ#1281979 monitorix-3.8.1 is available

Taskotron: upgradepath test FAILED on noarch. Result log: https://taskotron.fedoraproject.org/resultsdb/results/4869853 (results are informative only)

This update has been pushed to stable.

9 years ago

Please login to add feedback.

Metadata
Type
security
Severity
medium
Karma
1
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-1
Stable by Karma
1
Stable by Time
disabled
Dates
submitted
9 years ago
in testing
9 years ago
in stable
9 years ago
BZ#1281979 monitorix-3.8.1 is available
0
1

Automated Test Results