From mk at mathias-kettner.de Mon Jun 23 15:58:55 2014 From: mk at mathias-kettner.de (Mathias Kettner) Date: Mon, 23 Jun 2014 15:58:55 +0200 (CEST) Subject: Check_MK Werk 0983: Fix security issue in code of row selections (checkboxes) (CVSS 4.9 AV:N/AC:M/Au:S/C:N/I:P/A:P) Message-ID: <20140623135855.BBFD58145B@mail.mathias-kettner.de> ID: 0983 Title: Fix security issue in code of row selections (checkboxes) (CVSS 4.9 AV:N/AC:M/Au:S/C:N/I:P/A:P) Component: Multisite Level: 2 Class: Security Fix Version: 1.2.5i4 The fixed weakness was: The check_mk application does allow an attacker to write check_mk config files (.mk files) on arbitrary locations on the server filesystem.