NRPE: Multiple Vulnerabilities Multiple vulnerabilities have been found in NRPE, the worst of which can allow execution of arbitrary code. nrpe August 30, 2014 August 30, 2014: 1 397603 459870 508122 remote 2.15 2.15

Nagios Remote Plugin Executor (NRPE) remotely executes Nagios plugins on other Linux/Unix machines.

Multiple vulnerabilities have been discovered in NRPE. Please review the CVE identifiers referenced below for details.

A remote attacker can utilize multiple vectors to execute arbitrary code.

There is no known workaround at this time.

All NRPE users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-analyzer/nrpe-2.15"
CVE-2013-1362 CVE-2014-2913 underling BlueKnight