-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 22 May 2026 21:00:00 +1000 Source: nagios4 Binary: nagios4-common Architecture: all Version: 4.4.6-4+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-grnet-03) Changed-By: Russell Stuart Description: nagios4-common - support files for nagios4 Closes: 1136340 Changes: nagios4 (4.4.6-4+deb12u1) bookworm-security; urgency=high . * CSRF Security Fix backported from upstream 4.5.12 commit e5ed38e53a5d65721520c7c67be0746d63da28cb (cgi/cmd.c and html/index.php.in). See https://www.nagios.com/security-disclosures/nagios-core/4-5-12/ for the upstream disclosure. No CVE assigned. Closes: #1136340. * This can break third party integrations that POST to cmd.cgi without first setting NagFormId (the CSRF check fails). Upstream PR 1055 has been added as a workaround - see README.Debian. Checksums-Sha1: 71e2969abf06a3ef59372f1f48a0ad2d8c8b26ad 71364 nagios4-common_4.4.6-4+deb12u1_all.deb 3c0eaa24c832671d6a311e9aa63e3304291544f8 9441 nagios4_4.4.6-4+deb12u1_all-buildd.buildinfo Checksums-Sha256: 616c8674cbb6e1c10e70c256042d40efecb821dc5470bf35fbde9d0934b18627 71364 nagios4-common_4.4.6-4+deb12u1_all.deb 87ceb98a327df2313d252fc1f25ed73f878219b9b273adfd1d59dd9772a7d7dd 9441 nagios4_4.4.6-4+deb12u1_all-buildd.buildinfo Files: c953aaf563c976cb39c1632c46a3ca13 71364 net optional nagios4-common_4.4.6-4+deb12u1_all.deb 925f3dc8176c353b77be06bc236c584b 9441 net optional nagios4_4.4.6-4+deb12u1_all-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5ZI1lXv5WjhHIVjsN8Ugyu9dQiQFAmoWCg8ACgkQN8Ugyu9d QiTmjhAAnuK08JejsJ6bc18GhmmVB0rHUtdYJcVFLDSo8/SziuTJHk54VAh6eaD5 q8zumamsRRm9XQkk1tj779X5O8AQWvy/GUEmntc3uvA00v80FfAxNbVkyD+F8aLG P3O7sVXCJRm4mkF328RCcqPpZpmMqbB3+Dlydn+ec9Nczxmb5yHPZW3pFgBeFVKy QO3O5JZRD5vZ+BYx+PRkkGs0ceAt0r0sYN1LLXQsQ8qbdSNDCxgwIsqT0FaMn2hs P4ehOXc0eGocWwXsn01ePfY/tDSMQAvkeYDUokMErK0pJuwoaz7aVM7fBFv1HcHH KyXDll9LevBjZbITiuxuIMsaMVuSzjx6poo0xG/slQrz9zZd0fDozQ8glL2Uc0Rm 1JQ2APi7FsEPgrxIimG6qKOxNCIwqt/lIlFu/mpte21h8GhX4ZBW2PlowaxPpTYX 1nn+bIqfxeB4fNkKbTG4wvjlQVc2W8MHLBUplMNZXLWAyBxDm5VX1pyTCuEMZMZ7 x/ZYs7AyfznaU+rHLuPP0HV1/L4J/TaeM8wXTsxojyyP3/LMCB2XQQq9Lg4vSWMh Lf8SmPpkvXpZMy7RLdoyoknHQzCBs6qbId9NlS6sOx3S0k0cPKhBU/hqxrzew24L 18E26Gcb01QA08okOJtAidS3CcI5s5RGkLKBx2YRT7n5qvjL1oA= =W4yu -----END PGP SIGNATURE-----