[Xymon] Xymon 4.3.25 - Important Security Update

J.C. Cleaver cleaver at terabithia.org
Tue Feb 9 23:36:39 CET 2016



On Tue, February 9, 2016 1:27 pm, Ryan Novosielski wrote:

>
> Am I right that:
>
> A) The critical component to upgrade here is the server running the
> Xymon display (less so the xymonnnet machines, if any) and...
> B) A Xymon 4.3.12 xymonnet machine will operate correctly with a Xymon
> 4.3.25 server that is receiving the status messages and generating the
> web pages?


A) The most critical items are the CGI directory, correct. Typically
that's your Xymon display server, although strictly speaking it's possible
to have xymongen + page output, CGI scripts, and xymond on three different
servers.

If you can't update your core xymond server at this time, you should
validate the permissions on all files in your $XYMONHOME/etc/ directory to
ensure the user xymond is running as doesn't have read access to anything
it shouldn't.

B) Correct. You should be fine going from 4.3.12 reporting to a 4.3.25.
The reverse (new xymonnet to 4.3.12 xymond) won't work due to the new
extcombo format not being understood.


Regards,
-jc




More information about the Xymon mailing list