Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-8641

Опубликовано: 01 авг. 2018
Источник: nvd
CVSS3: 6.7
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:nagios:nagios:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:4.2.1:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:4.2.2:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:4.2.3:*:*:*:*:*:*:*

EPSS

Процентиль: 74%
0.00839
Низкий

6.7 Medium

CVSS3

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-59
CWE-59

Связанные уязвимости

CVSS3: 6.7
ubuntu
больше 7 лет назад

A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change.

CVSS3: 6.7
redhat
около 9 лет назад

A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change.

CVSS3: 6.7
debian
больше 7 лет назад

A privilege escalation vulnerability was found in nagios 4.2.x that oc ...

CVSS3: 7.8
github
больше 3 лет назад

A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change.

suse-cvrf
больше 7 лет назад

Security update for nagios

EPSS

Процентиль: 74%
0.00839
Низкий

6.7 Medium

CVSS3

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-59
CWE-59