Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9566

Опубликовано: 15 дек. 2016
Источник: debian
EPSS Средний

Описание

base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nagios3removedpackage
nagios3no-dsawheezypackage
icingafixed1.13.4-1package
icingano-dsajessiepackage
icingano-dsawheezypackage

Примечания

  • https://github.com/NagiosEnterprises/nagioscore/commit/c29557dec91eba2306f5fb11b8da4474ba63f8c4

  • https://legalhackers.com/advisories/Nagios-Exploit-Root-PrivEsc-CVE-2016-9566.html

  • nagios < 3.5 is not vulnerable through the regular logfile, but through the debug logfile

  • https://dev.icinga.com/issues/13709

  • https://github.com/Icinga/icinga-core/commit/a0eb8471673b6b1e9b37e1b7b91151aa00bedb65

  • https://github.com/Icinga/icinga-core/commit/e0f55bc9b17ef1db9aed7393fc34576a5b9501f0

EPSS

Процентиль: 93%
0.11231
Средний

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 9 лет назад

base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.

CVSS3: 7.3
redhat
около 9 лет назад

base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.

CVSS3: 7.8
nvd
около 9 лет назад

base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.

CVSS3: 7.8
github
больше 3 лет назад

base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.

suse-cvrf
около 9 лет назад

Security update for icinga

EPSS

Процентиль: 93%
0.11231
Средний