[Bug 728328] [NEW] nagios plugins depend on samba

rew 728328 at bugs.launchpad.net
Thu Mar 3 09:49:54 UTC 2011


*** This bug is a security vulnerability ***

Public security bug reported:

Binary package hint: nagios-plugins

I have an internet server. I like to keep as little as possible
installed. A package as "SAMBA' I simply do NOT want installed on my
server. It has no place there.

Now to get nagios to check my disk-free-status, I installed "nagios-
plugins". This depends on "samba-common" and samba-common-bin. It
stopped short of starting the samba server.

So, to monitor samba stuff, I imagine that having the samba tools
installed is required. But for my use this is not neccesary at all. This
sort of "attitude" causes software bloat. We/ubuntu should be careful in
what dependencies to mark as required.

Either split the nagios-plugins package into a nagios-plugins-samba, or
remove the dependency. In the latter case, you can make things "neat" by
editing the script that requires samba to print a nice: "you need to
install samba" if it isn't found.

And YES it is a security issue to have unneccesary software installed on
an internet server.

** Affects: nagios-plugins (Ubuntu)
     Importance: Undecided
         Status: New

** Visibility changed to: Public

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to nagios-plugins in ubuntu.
https://bugs.launchpad.net/bugs/728328

Title:
  nagios plugins depend on samba



More information about the Ubuntu-server-bugs mailing list