-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 22 May 2026 20:45:00 +1000 Source: nagios4 Binary: nagios4 nagios4-cgi nagios4-cgi-dbgsym nagios4-core nagios4-core-dbgsym Architecture: ppc64el Version: 4.4.6-4.1+deb13u1 Distribution: trixie-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-conova-02) Changed-By: Russell Stuart Description: nagios4 - host/service/network monitoring and management system nagios4-cgi - cgi files for nagios4 nagios4-core - host/service/network monitoring and management system core files Closes: 1136340 Changes: nagios4 (4.4.6-4.1+deb13u1) trixie-security; urgency=high . * CSRF Security Fix backported from upstream 4.5.12 commit e5ed38e53a5d65721520c7c67be0746d63da28cb (cgi/cmd.c and html/index.php.in). See https://www.nagios.com/security-disclosures/nagios-core/4-5-12/ for the upstream disclosure. No CVE assigned. Closes: #1136340. * This can break third party integrations that POST to cmd.cgi without first setting NagFormId (the CSRF check fails). Upstream PR 1055 has been added as a workaround - see README.Debian. Checksums-Sha1: 3202572e47b7098ae71ba0ff3ec01641f17e99f0 6115636 nagios4-cgi-dbgsym_4.4.6-4.1+deb13u1_ppc64el.deb aef5864de0582a1407efe666d627ea2ac374656b 1342624 nagios4-cgi_4.4.6-4.1+deb13u1_ppc64el.deb f82de1a19296805726e495d8895efb6c2303336e 776436 nagios4-core-dbgsym_4.4.6-4.1+deb13u1_ppc64el.deb b071b23eee522f77eb80fb704f22f2afe8b7cfec 273544 nagios4-core_4.4.6-4.1+deb13u1_ppc64el.deb ca3d45d3658c4d46aea1ed6244143224f34a6930 10215 nagios4_4.4.6-4.1+deb13u1_ppc64el-buildd.buildinfo 7be058b0d303b09952f3d57fa13718ca447d128f 16412 nagios4_4.4.6-4.1+deb13u1_ppc64el.deb Checksums-Sha256: 8bc63fa8e3ae6635d7fa4e68d129980067d6ad9ffaf73e401fccaad26c26ec6b 6115636 nagios4-cgi-dbgsym_4.4.6-4.1+deb13u1_ppc64el.deb 88a18d65484c6e1b108e0f6248367b93a1d01aeede489acd1257306016f4a751 1342624 nagios4-cgi_4.4.6-4.1+deb13u1_ppc64el.deb 19d5bca91aee41736c87b09691475a61e65b39ea4f32d6276d20dfcce57e6dcd 776436 nagios4-core-dbgsym_4.4.6-4.1+deb13u1_ppc64el.deb ad570b874ba3e43143a248e76ceb72ee4366bd7aa8508aad0b96efbbd15aac2f 273544 nagios4-core_4.4.6-4.1+deb13u1_ppc64el.deb 0cb8c13b4f693ca214ba3061e4fde638c9b82002b8c1c1db146d1d1b4c54e8cb 10215 nagios4_4.4.6-4.1+deb13u1_ppc64el-buildd.buildinfo c0fff3b197b2a49633a1ffe29d9b3ca72a2d88564232f5a6c0e8da30d12ab7fb 16412 nagios4_4.4.6-4.1+deb13u1_ppc64el.deb Files: 45b8ed092c75915bd758ec09a03b4cac 6115636 debug optional nagios4-cgi-dbgsym_4.4.6-4.1+deb13u1_ppc64el.deb e67f6298d3b6b4810faa3a1e7f2be2d7 1342624 net optional nagios4-cgi_4.4.6-4.1+deb13u1_ppc64el.deb 96edde04f80791d1a04a9b834563b30d 776436 debug optional nagios4-core-dbgsym_4.4.6-4.1+deb13u1_ppc64el.deb 7ce1803be3f816425f089691b4d4a1df 273544 net optional nagios4-core_4.4.6-4.1+deb13u1_ppc64el.deb c8383c9d3e7779ee3513fbae102b9c67 10215 net optional nagios4_4.4.6-4.1+deb13u1_ppc64el-buildd.buildinfo c95a7d71a32fc05868ab90006ce17905 16412 net optional nagios4_4.4.6-4.1+deb13u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEySUEQfg5pZeb/U372FRWNm40e2YFAmoVZWAACgkQ2FRWNm40 e2aarBAAuesBGVIib/33p7PQs3PUuBpXCZ1ykKOF9gLf6x1UEEBdP5YjM5SljWNU 2R7+4OH40PbO+TjH75F0+nh/NMt9CLrm9U8VS4rPsgpDCGaNPpiF/MPtWN8HQfMe INh1d9eumop+Kj/1ihlGI0oA09YybDu1KSagsroLH/1rIXDaUcEVUEwKkAn5122R D4zidaDtzuL3zMeTAoZBqL/ZaRPTcxqAtHu4oArvx0EdcgeGgCluHaxp4ICjZmOP eEcVyBDyit8Z6Obkklr1TpbMElWJpMTcQvvkAmMWuM9aREfqTPhZi2kfCAUEZyRv KZSbho0X5dkIEiH8q4fZA4EEaB1s+RHuWpunfw08Adpb0FX05eQ/1wOwa8JN9kGI K4kdJagTzl3CupBGLmeor9MHcBJnu4DIU+hq0vxIArZ06WNEhJTAWnByDQMd+M1g gtM4jwRin6omFfr/FUpRA3nenxBNrip6p6fgIc0SNHhn7CgajJ+STSiNaC2QGBDB LpWatVsN+dvWejesQEZ663t9jKw9Cg8xXdAWY91MgVf/TYA+uklQc67ervYVpF+9 77id4wbTDTvOyVYpcqSNZMg6JhS7filMGcW0cakzwXwldCob+eYDf6NVpnfHdSHf JNmazHZovs0Odttyw/U4NutEQfxRGD3jlPoQpvz7t8k2LMwMlCg= =zagH -----END PGP SIGNATURE-----