Changelog for
nagios-debuginfo-3.0.6-1.2.x86_64.rpm :
Mon Jun 29 14:00:00 2009 cschneemannAATTsuse.de
- fix nagios remote code exec via CGI (bnc#517311)
Tue Dec 9 13:00:00 2008 cschneemannAATTsuse.de
- update to 3.0.6:
+ Fix for CGI submission of external commands (writing newlines
and submitting service comments)
+ Fix for Apache group membership in RPM spec file
+ Fix for improper notification propagation command processing
+ Better out-of-disk-space error handling when writing retention
and status files
+ Disabled adaptive check and eventhandler commands for security
reasons
+ Fix for reading output from system commands (event handlers,
etc) that have timed out
+ Added wildcard host matching in CGIs
+ Fixes for playing audio alerts in CGIs
+ Fix for incorrect host status links in status CGI when viewing
hostgroup summary
+ Added support for x509 cert authentication in the CGIs
- fixes bnc#442275 : nagios: CSRF bug
Mon Dec 1 13:00:00 2008 lruppAATTsuse.de
- don\'t fail if the host has problems to execute newaliases
Mon Nov 10 13:00:00 2008 lruppAATTsuse.de
- update to 3.0.5:
+ Security fix for Cross Site Request Forgery (CSRF) bug reported
by Tim Starling.
+ Sample audio files for CGIs removed from distribution
+ Fix for mutliline config file continuation bug
+ Minor sample config file fix
+ Added documentation on CGI security issues
- added permissions-directory-setuid-bit for /var/spool/nagios
Tue Oct 28 13:00:00 2008 lruppAATTsuse.de
- use relative pathnames in %%post
Fri Oct 17 14:00:00 2008 lruppAATTsuse.de
- update to 3.0.4:
+ Fix for properly terminating plugins when parent processes get
killed (e.g. using \'killall nagios\' with check_timeout plugins
running)
+ Fix for event broker callback when service notifications are
disabled
+ Fix for scheduling scheduling servicegroup downtime with
\'hosts too\' option in CGIs
+ Fixes for bugs in sample event handlers - stop/start active
service checks and enable notifications
+ Cosmetic fix for logging of notifications
+ Fix for host/service name encoding in CGIs (trends and
availability reports, etc.)
Mon Sep 15 14:00:00 2008 lruppAATTsuse.de
- be a bit more secure in %post scripts
- fix ownership of resource file in init script
- enhance the README.SuSE a bit
- Recommend cron
Mon Jul 21 14:00:00 2008 lruppAATTsuse.de
- fix fillup call
- update to 3.0.3:
+ Minor bug fixes in CGIs
+ Minor bug fix in navigation frame
+ Better error logging during fork() errors
+ Fixed bug in parsing host dependencies
+ Updated p1.pl to allow for 4KB lines in Perl plugin output
+ Fixed bug in command for disabling contact notifications
+ Fix for bugs in host and service orphan check logic
+ Fix for properly escaping macros containing URLs
+ Patches for possible XSS vulnerability in CGIs (CVE-2007-5803)
+ Changes to service check event broker logic (DNX patches)
+ Fixes for url encoding
+ Fix for debug logging of notifications
+ Segfault fix in history CGI
+ Typo fix in object config routines
Thu May 29 14:00:00 2008 olhAATTsuse.de
- fix missing return value in run_async_service_check (bnc#395203)
Thu Apr 24 14:00:00 2008 olhAATTsuse.de
- require mailx (bnc#383209)
Tue Apr 22 14:00:00 2008 olhAATTsuse.de
- fix cron logfile-check in /var/log/nagios/archives/ (bnc#381857)
Thu Apr 3 14:00:00 2008 lruppAATTsuse.de
- update to 3.0.1:
+ Fixed bug in trends CGI with user not being authorized
for hosts/services
+ Fixed bug in status CGI with page layout messing up when
sounds enabled
Thu Mar 13 13:00:00 2008 lruppAATTsuse.de
- update to 3.0 (final):
+ Faster program startup times (especially in large installs)
with new object lookup code
+ Fix for special contact inheritance rules in
host and service escalations
+ Fix for bug in processing $CONTACTADDRESSx$ macros
+ Documentation fixes
- Recommend perl
Wed Mar 5 13:00:00 2008 lruppAATTsuse.de
- update to 3.0rc3:
+ New macros have been added
+ The old $NOTIFICATIONNUMBER$ macro has been deprecated in favor
of new $HOSTNOTIFICATIONNUMBER$ and $SERVICENOTIFICATIONNUMBER$
macros.
+ The $HOSTNOTES$ and $SERVICENOTES$ macros may now contain
macros themselves
+ new \'enable_environment_macros\' option, which allow to disable
global macros for use in check, event handler, notification,
and other commands on large installations
+ scheduled downtime entries are now stored in the status file
and retention file, respectively
+ Current and retained comments are now stored in the status file
and retention file, respectively
+ Acknowledgement comments that are marked as non-persistent are
now only deleted when the acknowledgement is removed.
+ Comment and downtime IDs are now retained across program
restarts and should be unique unless the retention data is
deleted or ignored.
+ Added flap_detection_options directive to host and service
definitions to allow you to specify what host/service states
should be used by the flap detection logic
+ Added a new PROCESS_FILE external command to allow processing
of external commands found in an eternal (regular) file.
+ Contact status information (last notification times,
notifications enabled/disabled, etc.) is now saved in the
status and retention files, although it is not processed
by the CGIs.
+ check timeperiod for hosts and services can now be modified
on-the-fly
+ Multiline plugin output is now supported for host and
service checks
+ Nagios now checks for orphaned service checks by default.
+ Host checks are now run in parallel
+ Timeperiods were overdue for a major overhaul
+ Added event broker callbacks for adaptive programm and contact
status data
+ ... (See ChangeLog for more details)
- Logfiles are stored in /var/log/nagios now
- Nagios uses own logrotation - but we bzip the old logfiles via
weekly cronjob (Requires: bzip2)
- added sysconfig file for timeout and nice level
- overhaul the init script
- added a README.SuSE
- added rpmlintrc
- added config.err file as %ghost
- use upstream macros for all steps during rpmbuild where possible
- adapt to work on all (open)SUSE distributions
- overhaul the patches
- cmdusr is now wwwrun and not nobody
- cmdgrp is now new group nagcmd and not www
- split out devel package
- enable event-broker
- use upstream apache config
- adapt the generated sample configurations so the work out of the
box
- enable template-objects
- prepare and own the directory for event brokers
- include all sample configuration in docdir
- use fdupes
- create/update new groups/users in %pre of the (sub-)package
- add the apache2 user to the nagcmd group in %post of nagios-www
- restart apache2 if nagios-www changes
- own some %ghost files with the correct permissions
Fri Oct 26 14:00:00 2007 tsiedenAATTsuse.de
- update to nagios version 2.10
* Added \'make install-webconf\' command to install Apache web config file
* Sample config files are now installed without a -sample extension
* Fix for SIGTERMs being seen as SIGEXITs, non-logging of SIGTERMs/shutdowns
* Minor fix for notification timeout log messages
* Fix for not logging passive host check results
* Minor bug fixes in CGIs
* Fix for a segfault when processing passive host check results with empty output/perfdata
* Fix for incorrect latency calculation for passive service checks
* Bug fix with attempting to access an uninitalized mutex if external commands are disabled
* Fix for keeping service checks in the event queue when active service checks are disabled globally
* Fix for a potential cross site scripting vulnerability in the CGIs
* Program version is now displayed in CGIs
- removed obsolete FAQ patch in html/docs dir
Sun Sep 16 14:00:00 2007 cschneemannAATTsuse.de
- added openssl-devel to BuildRequires to support SSL in check_http
Sun Aug 12 14:00:00 2007 olhAATTsuse.de
- move p1.pl to /usr/lib/nagios/p1.pl
set 0755 permissions for executable files (157814)
Wed May 16 14:00:00 2007 lruppAATTsuse.de
- build on older distributions:
BuildRequires: libapr0 XFree86-devel XFree86-libs
Fri May 4 14:00:00 2007 tsiedenAATTsuse.de
- update to nagios version 2.9
* Fix for incorrect performance data file write/append mode options
* Fix for current status of hosts with no host check command defined
* SIGSEGV signals should now be logged again (broken in 2.8)
* Configure script fix for no mail program found/installed on system
* Configure script option bug fixes for cygwin and embedded perl
* Command definitions and host/service plugin perfdata with HTML should now be escaped in CGIs
* Patch for incorrect time down percentage in availability CGI
* Updated init script to fix a race condition during restarts
Mon Mar 12 13:00:00 2007 tsiedenAATTsuse.de
- update to nagios version 2.8
* Bug fix for calculating notification interval with service escalations
* Bug fix for using servicegroups in service dependency definitions
* Bug fix for bad date format submission in command CGI
* Possible segfault fix during restarts when daemon was performing host checks
* Fix for missing check timeout in event broker calls
* Fix for handling signals under NPTL
* Added error messages for passive service checks that don\'t correspond to a defined service
Fri Feb 9 13:00:00 2007 tsiedenAATTsuse.de
- update to nagios version 2.7
* p1.pl now sets environment var (NAGIOS_PLUGIN) to indicate patch of plugin that is executing
* Updated nagiostats with new MRTG vars for tracking buffer usage
* Added sample MRTG config file
* Minor patches to availability and status CGIs
* Minor documentation updates
* Fix for segfault during expiration or deletion of scheduled downtime
* Fix for scheduling immediate service check through WAP interface
* Fix for leading whitespace before comments in object config files
Thu Feb 1 13:00:00 2007 olhAATTsuse.de
- add quick-start.txt (#237372)
Thu Feb 1 13:00:00 2007 olhAATTsuse.de
- remove unneeded trailing slashes from Alias and Directory entries
in nagios-http.conf
Wed Jan 17 13:00:00 2007 olhAATTsuse.de
- fix more comparison with string literal in avail.c
Thu Jan 11 13:00:00 2007 olhAATTsuse.de
- FATE #301512
Thu Jan 11 13:00:00 2007 olhAATTsuse.de
- fix typo in html docu, perdata.html -> perfdata.html
Thu Jan 11 13:00:00 2007 olhAATTsuse.de
- correct link to external FAQ website
Thu Jan 11 13:00:00 2007 olhAATTsuse.de
- correct Alias in nagios-httpd.conf
Wed Jan 10 13:00:00 2007 olhAATTsuse.de
- update the default example config to mail to nagios%localhost
instead to non-existant nagios-admin%localhost
Wed Jan 10 13:00:00 2007 olhAATTsuse.de
- fix comparison with string literal (#232415)
Mon Jan 8 13:00:00 2007 olhAATTsuse.de
- move pid file to /var/run/nagios/ (#231169)
Fri Dec 1 13:00:00 2006 tsiedenAATTsuse.de
- update to version 2.6
* fix for unscheduled triggered downtime entries
* fix for embedded audio in tac and status CGIs
* fixed bug in nagiostats utility when reporting host/service check latency
* misc code cleanups for compiler warnings
* fixed error when reading empty (zero byte) config files
* default is now to check for orphaned service checks (Francois Caen)
* fixed bug with non-standard CGI config file location in status data (Carson Gaspar)
* fixed bugs and simplified examples in sample config files (Mark Young)
* removed obsolete patches which are included in upstream now
- fixed \"empty PID file error\" in init script
Thu Nov 16 13:00:00 2006 tsiedenAATTsuse.de
- changed home dir to /var/lib/nagios (#221791)
Tue Oct 17 14:00:00 2006 olhAATTsuse.de
- fix uninitialized variable in run_global_service_event_handler (212892)
Mon Sep 18 14:00:00 2006 olhAATTsuse.de
- add a user/group nagios (#61908)
Fri Sep 8 14:00:00 2006 olhAATTsuse.de
- update to version 2.5
disable sapmon patch for the time being