Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-16933

Опубликовано: 24 нояб. 2017
Источник: debian
EPSS Низкий

Описание

etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gain privileges by leveraging access to the $ICINGA2_USER account for creation of a link.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
icinga2fixed2.8.4-1package
icinga2no-dsastretchpackage
icinga2no-dsajessiepackage

Примечания

  • https://github.com/Icinga/icinga2/issues/5793

  • Fixed by: https://github.com/Icinga/icinga2/commit/5aafc7eda5c1b026a993fc2782fa84b8f3e8e052 (v2.8.2)

  • CVE is for the unsafe use of chown(1)

EPSS

Процентиль: 8%
0.0003
Низкий

Связанные уязвимости

CVSS3: 7
ubuntu
около 8 лет назад

etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gain privileges by leveraging access to the $ICINGA2_USER account for creation of a link.

CVSS3: 7
nvd
около 8 лет назад

etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gain privileges by leveraging access to the $ICINGA2_USER account for creation of a link.

CVSS3: 7
github
больше 3 лет назад

etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gain privileges by leveraging access to the $ICINGA2_USER account for creation of a link.

EPSS

Процентиль: 8%
0.0003
Низкий