-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 22 May 2026 20:45:00 +1000 Source: nagios4 Binary: nagios4-common Architecture: all Version: 4.4.6-4.1+deb13u1 Distribution: trixie-security Urgency: high Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Russell Stuart Description: nagios4-common - support files for nagios4 Closes: 1136340 Changes: nagios4 (4.4.6-4.1+deb13u1) trixie-security; urgency=high . * CSRF Security Fix backported from upstream 4.5.12 commit e5ed38e53a5d65721520c7c67be0746d63da28cb (cgi/cmd.c and html/index.php.in). See https://www.nagios.com/security-disclosures/nagios-core/4-5-12/ for the upstream disclosure. No CVE assigned. Closes: #1136340. * This can break third party integrations that POST to cmd.cgi without first setting NagFormId (the CSRF check fails). Upstream PR 1055 has been added as a workaround - see README.Debian. Checksums-Sha1: ae3cc9adbe8a23f4b5e31ecbd515f1a7c537d424 71468 nagios4-common_4.4.6-4.1+deb13u1_all.deb fc90b8cdf177babbd69b579690342f545ea67278 8968 nagios4_4.4.6-4.1+deb13u1_all-buildd.buildinfo Checksums-Sha256: a74bda6f7af510eb47b80809623f6916d282946d77f1ca26fa5507ac2ba4e302 71468 nagios4-common_4.4.6-4.1+deb13u1_all.deb cde076bcb679908f0475a135458cd11e76df44a734ef6f398aee063d70a0605a 8968 nagios4_4.4.6-4.1+deb13u1_all-buildd.buildinfo Files: 56d1843cecd3ba59ef33c3925597360a 71468 net optional nagios4-common_4.4.6-4.1+deb13u1_all.deb cc79c8968670229fb34ceaa2909c3895 8968 net optional nagios4_4.4.6-4.1+deb13u1_all-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE81O8NL+3kjBAqEvLmgPNRvTf/zcFAmoVZUAACgkQmgPNRvTf /zfkkBAAk9c/K6P6YuO/Qp6gRtMsYDHcgN3vdPY+2w88zU7gVKE3R5snssubZbJL lZVdsDkUviHx+WQf/kcRIkbz0bB6IMdza62cSDbmLPFxBVTRzWVbYLM+s7ueebTQ TVQrZ/Nk+J0tyCFk6e3vULn6SCvqOyOms0OKdoejGh76rCSJEt1G/88CBB2E4UQc lWOR5uadQxuAwaWdomtvnAFS1lXRPnpfbESDTfUr2OP0de+leSSLYVfhE0O1ZwoI 7x3aaz6Y5XC7TUdCDQAg8Yw6C42UKYDes/DMUfFVIxtZqlDiUBbvDNoCYQwUnc2K WwFCXqEx5vRvHjlSHK6DCPcqA7q6s9oTOey01/UdS9K14k902O51+Hf9gGkCh7ZR zGF+AqGFMpvNkKXrFeJ1/1qG2gMUiyKLAifPUPab35QovrpDAanNHuUZ8Hwy6rGt lYEqeyF6FAVR7t+kUwFb7eo+vFwO+dgP9QV8dIfBzE4N8wqm/ZLUmyVcp3ku1CSX 6LOsRgoK/+KlP+BY/AkvYUHym0C9fi8lFMTHVvBjzwEwpzCrzgs194rEMTw+4Zo8 ir7z3GWHxRrfpcQQXDv1XlXaRfP6H25aUxPgvXam/Tta7JmMmNdwP0rnNTmoDpX8 73rtJFZRjzW1YuzQSjY4bWh7aBK158VDqrrxRhHAnH0nY5dqOSo= =ij2o -----END PGP SIGNATURE-----