nagios4 (4.4.6-4+deb12u2) bookworm-security; urgency=high

  * The CSRF fix previously backported in 4.4.6-4+deb12u1 is now
    tracked as CVE-2026-48548.
  * Backport upstream 4.5.13 and 4.5.14 security fixes:
    - CSRF protection bypass in cmd.cgi, where a request sending no
      Cookie header could supply both halves of the double-submit
      cookie itself (CVE-2026-48549).
    - Reflected XSS in cmd.cgi via the NagFormId parameter
      (CVE-2026-48550).
    - CSRF protection bypass via a self-supplied double-submit cookie
      (CVE-2026-48551).
    - DOM-based XSS in jsonquery.js (CVE-2026-48552).
    - Authenticated remote code execution via custom-variable macro
      injection (CVE-2026-48553).
    - Authenticated remote code execution via unfiltered
      NOTIFICATION-family macro substitution (CVE-2026-48554).
  * Fix a one-element heap overflow in getcgivars() when a request with
    no parameters carries a NagFormId cookie.  No CVE assigned.

 -- Russell Stuart <russell-debian@stuart.id.au>  Mon, 31 Aug 2026 19:56:29 +1000

nagios4 (4.4.6-4+deb12u1) bookworm-security; urgency=high

  * CSRF Security Fix backported from upstream 4.5.12 commit
    e5ed38e53a5d65721520c7c67be0746d63da28cb (cgi/cmd.c and
    html/index.php.in).  See
    https://www.nagios.com/security-disclosures/nagios-core/4-5-12/
    for the upstream disclosure.  No CVE assigned.
    Closes: #1136340.
  * This can break third party integrations that POST to cmd.cgi
    without first setting NagFormId (the CSRF check fails).  Upstream
    PR 1055 has been added as a workaround - see README.Debian.

 -- Russell Stuart <russell-debian@stuart.id.au>  Fri, 22 May 2026 21:00:00 +1000

nagios4 (4.4.6-4) unstable; urgency=low

  * Fix syntax in nagios4.service.  Closes: #986397.

 -- Russell Stuart <russell-debian@stuart.id.au>  Wed,  7 Apr 2021 20:43:46 +1000

nagios4 (4.4.6-3) unstable; urgency=low

  * Fix nagios4-ci not installing with recommends.  Closes: #985043.

 -- Russell Stuart <russell-debian@stuart.id.au>  Mon, 22 Mar 2021 12:10:04 +1000

nagios4 (4.4.6-2) unstable; urgency=low

  * Source only upload for migration to testing.

 -- Russell Stuart <russell-debian@stuart.id.au>  Mon, 23 Nov 2020 18:48:30 +1000

nagios4 (4.4.6-1) unstable; urgency=low

  * New release - fixes memory leak.
  * Fix bad apache2 config.  Closes: #931664
  * Don't remove js function set_limit().  Closes: #945219
  * Enable apache2 authz_groupfile on nagios4-cgi install.  Closes: #931664.

 -- Russell Stuart <russell-debian@stuart.id.au>  Thu, 20 Aug 2020 20:04:50 +1000

nagios4 (4.3.4-3) unstable; urgency=low

  * Fix CVE-2018-18245 (closes: #902138)
  * Fix CVE-2018-13441, CVE-2018-13457, CVE-2018-13458 (closes: #917160)
  * Removed /etc/nagios4/htdigest.users purge (closes: #905523)
  * Fix unknown RPM_ARCH (closes: #902216)

 -- Russell Stuart <russell-debian@stuart.id.au>  Thu,  7 Feb 2019 19:35:53 +1000

nagios4 (4.3.4-2) unstable; urgency=low

  * Remove lookup of nagios_check_command from nagios4.init.  It
    doesn't exist in nagios4.

  * ITP (closes: #894696)

 -- Russell Stuart <russell-debian@stuart.id.au>  Mon,  9 Apr 2018 17:20:50 +1000
