Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-8641

Опубликовано: 01 авг. 2018
Источник: nvd
CVSS3: 6.7
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:nagios:nagios:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:4.2.1:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:4.2.2:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:4.2.3:*:*:*:*:*:*:*

EPSS

Процентиль: 64%
0.01141
Низкий

6.7 Medium

CVSS3

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-59
CWE-59

Связанные уязвимости

CVSS3: 6.7
ubuntu
около 8 лет назад

A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change.

CVSS3: 6.7
redhat
больше 9 лет назад

A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change.

CVSS3: 6.7
debian
около 8 лет назад

A privilege escalation vulnerability was found in nagios 4.2.x that oc ...

CVSS3: 7.8
github
больше 4 лет назад

A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change.

suse-cvrf
почти 8 лет назад

Security update for nagios

EPSS

Процентиль: 64%
0.01141
Низкий

6.7 Medium

CVSS3

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-59
CWE-59