-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 22 May 2026 20:45:00 +1000 Source: nagios4 Binary: nagios4 nagios4-cgi nagios4-cgi-dbgsym nagios4-core nagios4-core-dbgsym Architecture: s390x Version: 4.4.6-4.1+deb13u1 Distribution: trixie-security Urgency: high Maintainer: s390x Build Daemon (ziehrer) Changed-By: Russell Stuart Description: nagios4 - host/service/network monitoring and management system nagios4-cgi - cgi files for nagios4 nagios4-core - host/service/network monitoring and management system core files Closes: 1136340 Changes: nagios4 (4.4.6-4.1+deb13u1) trixie-security; urgency=high . * CSRF Security Fix backported from upstream 4.5.12 commit e5ed38e53a5d65721520c7c67be0746d63da28cb (cgi/cmd.c and html/index.php.in). See https://www.nagios.com/security-disclosures/nagios-core/4-5-12/ for the upstream disclosure. No CVE assigned. Closes: #1136340. * This can break third party integrations that POST to cmd.cgi without first setting NagFormId (the CSRF check fails). Upstream PR 1055 has been added as a workaround - see README.Debian. Checksums-Sha1: 0cf7c2dd95ff504d810beaeec0d45036a1dc6bb2 5655068 nagios4-cgi-dbgsym_4.4.6-4.1+deb13u1_s390x.deb c027e144138fd26f3fa9354870e5c594b801ebb4 1247344 nagios4-cgi_4.4.6-4.1+deb13u1_s390x.deb 035e45f534f18ead906cf90ff21673cb3cea5ede 745668 nagios4-core-dbgsym_4.4.6-4.1+deb13u1_s390x.deb 9f3e19eb9e9e933671b6804d746b371499aa5b5a 238356 nagios4-core_4.4.6-4.1+deb13u1_s390x.deb 95ba8af040d18dcad2c9adef50690e963443cf7b 9942 nagios4_4.4.6-4.1+deb13u1_s390x-buildd.buildinfo bf6157e61103e68f8daab8f49211a1e6122794f8 16412 nagios4_4.4.6-4.1+deb13u1_s390x.deb Checksums-Sha256: 8c8e9c189f125766344fc49985871196ec40251bf0d1e1729493c4f17b0e03da 5655068 nagios4-cgi-dbgsym_4.4.6-4.1+deb13u1_s390x.deb 0b8313054b6b8d26a5a0ddbf385206a2c1467638dcda6199e5d65687cc03a77d 1247344 nagios4-cgi_4.4.6-4.1+deb13u1_s390x.deb 8358ed9739419e6e66095a9b4fdd0da1cb6e113968ebf04a5d69a49128bd7ec1 745668 nagios4-core-dbgsym_4.4.6-4.1+deb13u1_s390x.deb 4fb67434e1ac9ce4cb515a15fce205a4ac2cfe095a88a0bba386d421a6b7cee7 238356 nagios4-core_4.4.6-4.1+deb13u1_s390x.deb a6b6cbfd1c7b9792f21afa31c6d95bc16622f2c348f2f5516b3667d9e2665279 9942 nagios4_4.4.6-4.1+deb13u1_s390x-buildd.buildinfo 48f39db6e6e075dd52af35df61cb44b0107af624cc151d57b85ccc7c2a6a0cc9 16412 nagios4_4.4.6-4.1+deb13u1_s390x.deb Files: 7565eebdb4f739e1450ffde6bff9c360 5655068 debug optional nagios4-cgi-dbgsym_4.4.6-4.1+deb13u1_s390x.deb 9dac7122c5a7d435b4973d0aa33f3d36 1247344 net optional nagios4-cgi_4.4.6-4.1+deb13u1_s390x.deb 887c820c429f220994218dff53290644 745668 debug optional nagios4-core-dbgsym_4.4.6-4.1+deb13u1_s390x.deb 6ba507dd81aa063c516246dd92a65e65 238356 net optional nagios4-core_4.4.6-4.1+deb13u1_s390x.deb a7e3e25dbd55d10f4daae5b7ce07c7f9 9942 net optional nagios4_4.4.6-4.1+deb13u1_s390x-buildd.buildinfo 488c0729bd6d65140336f12ac9e8e912 16412 net optional nagios4_4.4.6-4.1+deb13u1_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEl0BM/nR+Oj597wRWMWUFebkHnoQFAmoVZSMACgkQMWUFebkH noQCBw/+JUDwWSBvWPYxPkAiWXfdzK9PVWyjYxBc+PNXFe0XjzVuPPhbe3SPH4Gn ATfZY1W53S0uLRx6g3M6J4svy0+HhBar6XzC8UgQ6cmiBXltUF1IZhBe0vOLC+GJ 6tS7G8Z8+m4u8TbZo7+r7Bnk3S/kl+PSw85mO18pv+EBj8rva9SlE06BgMPOmiv1 5dWS2EbVjHB9rB2wxNFV7D3QHpsh942X/2DBTZE5HQJ9BfMWOj792eU/LTXuFz34 /74c01ONSeMmBcFzedwHKOt1qZHjGRG9vBUf8oUhZW0D++npsx/qEFPt9UQgUm+/ /U84Cqf7I8jbyHebanTY3ZOy5R+pYkjEpaCYEe5uzy3ONUI0D5AKIY/LtHZsOaj6 vwFsV8C2HLrQVgnynXhOYmPUKh7ohHfwvR61ePnpwz/jiqIaolzbjwM3+jlAYuax elhr4Tn1dMdCgkdAUAIl+NkDy69nFOjqWNxn0BpifMgWAJacr6AzqeSv217UAv+f LhJZYDCIYk6TrvVrYiEnFPuBTTAASxzcxFhBftN872CuPSa7aoppPVByWspX66oh 8cYCWrZRNtFdTBhONVGEMI043Le6u8ksCSTUfyTvU64vE37RYhB89mZM6QM+JbD3 cYhr3YnMKIT4LBA8yEXV54fUGSL199YItnEKVT8Z1CuGBKA6BTs= =eh4O -----END PGP SIGNATURE-----