Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.BUGS.RC
  • Bug#1106686: nagvis: CVE-2024-38866 CVE-2024-47090

    From Salvatore Bonaccorso@21:1/5 to All on Tue May 27 22:00:01 2025
    Source: nagvis
    Version: 1:1.9.46-1
    Severity: grave
    Tags: security upstream
    X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
    Control: fixed -1 1:1.9.47-1~exp1

    Hi,

    The following vulnerabilities were published for nagvis.

    Making the severity RC as the fixes should go into trixie before
    trixie release.

    CVE-2024-38866[0]:
    | Improper neutralization of input in Nagvis before version 1.9.47
    | which can lead to livestatus injection


    CVE-2024-47090[1]:
    | Improper neutralization of input in Nagvis before version 1.9.47
    | which can lead to XSS


    If you fix the vulnerabilities please also make sure to include the
    CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

    For further information see:

    [0] https://security-tracker.debian.org/tracker/CVE-2024-38866
    https://www.cve.org/CVERecord?id=CVE-2024-38866
    https://github.com/NagVis/nagvis/commit/6493722cf52436dbafb2b9f1c20c3ab8b663ad0f
    [1] https://security-tracker.debian.org/tracker/CVE-2024-47090
    https://www.cve.org/CVERecord?id=CVE-2024-47090
    https://github.com/NagVis/nagvis/commit/5baf87d30175357aaa39e42ff0d99fb0abefbc06

    Please adjust the affected versions in the BTS as needed.

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • Who's Online

  • Recent Visitors

    • Spearb0y
      Sun Jun 7 07:41:05 2026
      from Massachusetts via SSH
    • Krenn
      Sun Jun 7 03:07:26 2026
      from Sydney, Nsw via Telnet
    • Krenn
      Sun Jun 7 01:30:12 2026
      from Sydney, Nsw via Telnet
    • Centurion
      Sat Jun 6 23:27:30 2026
      from Berea, Ohio via Telnet
    • Ab Cadd
      Sat Jun 6 15:42:53 2026
      from Sheboygan, Wi via Telnet
    • Centurion
      Sat Jun 6 15:32:28 2026
      from Berea, Ohio via Telnet
    • Krenn
      Sat Jun 6 11:38:56 2026
      from Sydney, Nsw via Telnet
    • Furryboy
      Sat Jun 6 10:56:29 2026
      from Romania, Galati via SSH
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (0 / 16)
    Uptime: 164:22:48
    Calls: 12,095
    Calls today: 3
    Files: 15,000
    Messages: 6,517,797

© >>> Magnum BBS <<<, 2026