Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-6533

Опубликовано: 27 фев. 2018
Источник: debian

Описание

An issue was discovered in Icinga 2.x through 2.8.1. By editing the init.conf file, Icinga 2 can be run as root. Following this the program can be used to run arbitrary code as root. This was fixed by no longer using init.conf to determine account information for any root-executed code (a larger issue than CVE-2017-16933).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
icinga2fixed2.8.4-1package
icinga2no-dsastretchpackage
icinga2no-dsajessiepackage

Примечания

  • https://github.com/Icinga/icinga2/pull/5850

  • CVE is related to CVE-2017-16933 but for "the issue in using

  • init.conf to support run-time reconfiguration of an account is

  • design flaw". CVE-2018-6533 larger issue than CVE-2017-16933.

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 8 лет назад

An issue was discovered in Icinga 2.x through 2.8.1. By editing the init.conf file, Icinga 2 can be run as root. Following this the program can be used to run arbitrary code as root. This was fixed by no longer using init.conf to determine account information for any root-executed code (a larger issue than CVE-2017-16933).

CVSS3: 7.8
nvd
почти 8 лет назад

An issue was discovered in Icinga 2.x through 2.8.1. By editing the init.conf file, Icinga 2 can be run as root. Following this the program can be used to run arbitrary code as root. This was fixed by no longer using init.conf to determine account information for any root-executed code (a larger issue than CVE-2017-16933).

CVSS3: 7.8
github
больше 3 лет назад

An issue was discovered in Icinga 2.x through 2.8.1. By editing the init.conf file, Icinga 2 can be run as root. Following this the program can be used to run arbitrary code as root. This was fixed by no longer using init.conf to determine account information for any root-executed code (a larger issue than CVE-2017-16933).