-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 22 May 2026 21:00:00 +1000 Source: nagios4 Binary: nagios4 nagios4-cgi nagios4-cgi-dbgsym nagios4-core nagios4-core-dbgsym Architecture: mipsel Version: 4.4.6-4+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Russell Stuart Description: nagios4 - host/service/network monitoring and management system nagios4-cgi - cgi files for nagios4 nagios4-core - host/service/network monitoring and management system core files Closes: 1136340 Changes: nagios4 (4.4.6-4+deb12u1) bookworm-security; urgency=high . * CSRF Security Fix backported from upstream 4.5.12 commit e5ed38e53a5d65721520c7c67be0746d63da28cb (cgi/cmd.c and html/index.php.in). See https://www.nagios.com/security-disclosures/nagios-core/4-5-12/ for the upstream disclosure. No CVE assigned. Closes: #1136340. * This can break third party integrations that POST to cmd.cgi without first setting NagFormId (the CSRF check fails). Upstream PR 1055 has been added as a workaround - see README.Debian. Checksums-Sha1: e7ba3fb3f40fc9875ea4737729786779afbc735e 5848240 nagios4-cgi-dbgsym_4.4.6-4+deb12u1_mipsel.deb 5cc11feda642bfa248477cd44cb797239ff2fb37 1237408 nagios4-cgi_4.4.6-4+deb12u1_mipsel.deb 5bad998f89e60deb2ca310a7ef0512d95a9a085e 778964 nagios4-core-dbgsym_4.4.6-4+deb12u1_mipsel.deb 04936848ab96539d1a8f1b7eeb286555f27c7334 209084 nagios4-core_4.4.6-4+deb12u1_mipsel.deb 8b90386c90cfc723609c18e26079079183afd737 10437 nagios4_4.4.6-4+deb12u1_mipsel-buildd.buildinfo f4d4924651d3ecfd522a5dc3314d770d5e38cb0b 16300 nagios4_4.4.6-4+deb12u1_mipsel.deb Checksums-Sha256: c566bf80afdbebc0afe8b8013b41249eebbd3e14f75d9f0cc35e6d2d8d6f08f7 5848240 nagios4-cgi-dbgsym_4.4.6-4+deb12u1_mipsel.deb c025731a1b57e23623d22d18d91da84f940d885638f5f6e8498276cc7bbedb8f 1237408 nagios4-cgi_4.4.6-4+deb12u1_mipsel.deb 03e58e10d478473ca45b623038efa0fb44f4bbc431d8d1b5f5f1c64688bfe308 778964 nagios4-core-dbgsym_4.4.6-4+deb12u1_mipsel.deb 3e2b5c5635e3abfb18d835b76ce255a31f2b0450af516246c6f87fd3ace5ac51 209084 nagios4-core_4.4.6-4+deb12u1_mipsel.deb ceb69b1464c089dbf012a63ab6110658353b471fb61af5e932116da63cf05adf 10437 nagios4_4.4.6-4+deb12u1_mipsel-buildd.buildinfo ba5f93c998014dd140eb7106756850dead35a76a1630d8ab71e5c52eb0ee4782 16300 nagios4_4.4.6-4+deb12u1_mipsel.deb Files: 14647569661d9e095b774368a0430aeb 5848240 debug optional nagios4-cgi-dbgsym_4.4.6-4+deb12u1_mipsel.deb 878a0c7d0709a148d22e87353e53c387 1237408 net optional nagios4-cgi_4.4.6-4+deb12u1_mipsel.deb 81c89b759ad18417ffdef4ceee803436 778964 debug optional nagios4-core-dbgsym_4.4.6-4+deb12u1_mipsel.deb 7650b6a00fae682fbd2dd813179039fa 209084 net optional nagios4-core_4.4.6-4+deb12u1_mipsel.deb 907549c0ab841457e5ace04c449305ba 10437 net optional nagios4_4.4.6-4+deb12u1_mipsel-buildd.buildinfo 1db17fe1a4c7db633c524066ce868e30 16300 net optional nagios4_4.4.6-4+deb12u1_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE4ZxaH3zEHAF/GhnCHrk2gTKeWggFAmoWCg0ACgkQHrk2gTKe Wgj53A/+Ieq3KttKJRJbmXZAzx7ZsmDZXtG0ZGyVnNBm0Ozb/u2NPk8l9zaHljCO bKR9x1OEZ7cppo5uuT6Dp5AT3IdFMNEJl0ZbkJlE79dKCcZPrEoRPHDshjI8OHgS 0MTzz/fMPIVTBLGtqSWGzhGhDsf8+DHGE+3KtskjFXXd/aT53U7FRoz4vTyIh3RH Pxhi0OTXILQVFX7vF41FZIuVnpnw1MLBLXHibFaE9ajAv9NMuOVJIzXINp1hA0N6 m5PHpx+WPH4fucrSmeqp0gaVLYeOhfG/giXPVAJXjjHkYVA1VMkyl8gwTrCfFR+h 69j7HiT/jvkO3A7SIb3+4tyl52Rcy1OhCl84LifgzM+C2gkG4gdwm4E+8K/zUNNb 2BiZxcdcI6ob72oyRnJHB9h3cC5f++X9BVlW4EDGeGffDnr6GbETJW0Sxiy71nTe lcLUKI2N89SQvO0BWaHKypg7jGCTqqs3r+3GcFoIJxJ4rNYkxFZddZdLfrDXFx8m CWP0w9TMbrrm4FetuCLiP4FEvleL+6MP+RqQv7J1E+2PgyyRgGowv2PnUflXJ7GY ZQtH+owi30zcO6RCSwm4jUpTCLi5R3EY9lTqI+c3ytkvEbR5oGcngDcu7FkYgRUJ SwRJYnLbFl0QiXOwVtdeX9MySf9p1H+ezAXfHSkUol15keODdk0= =34xG -----END PGP SIGNATURE-----