Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-10089

Опубликовано: 30 дек. 2016
Источник: redhat
CVSS3: 6.7
EPSS Низкий

Описание

Nagios 4.3.2 and earlier allows local users to gain root privileges via a hard link attack on the Nagios init script file, related to CVE-2016-8641.

A vulnerability was found in Nagios 4.2.4, and earlier, which allows local users to gain root privileges via a hard link attack on the Nagios init script file, related to CVE-2016-8641.

Отчет

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Меры по смягчению последствий

This flaw, and others like it, are mitigated by enabling hardlink and symlink protections. These protections are enabled by default in Red Hat Enterprise Linux 7 and this vulnerability will only be exploitable if disabled. Ensure the following protections are enabled: sysctl -w fs.protected_hardlinks=1 sysctl -w fs.protected_symlinks=1

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)nagiosWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)nagiosWill not fix
Red Hat Mobile Application Platform 4nagiosNot affected
Red Hat Storage 3nagiosWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=1510927nagios: Privilege escalation due to incomplete fix for CVE-2016-8641

EPSS

Процентиль: 28%
0.00099
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 9 лет назад

Nagios 4.3.2 and earlier allows local users to gain root privileges via a hard link attack on the Nagios init script file, related to CVE-2016-8641.

CVSS3: 7.8
nvd
почти 9 лет назад

Nagios 4.3.2 and earlier allows local users to gain root privileges via a hard link attack on the Nagios init script file, related to CVE-2016-8641.

CVSS3: 7.8
debian
почти 9 лет назад

Nagios 4.3.2 and earlier allows local users to gain root privileges vi ...

CVSS3: 7.8
github
больше 3 лет назад

Nagios 4.3.2 and earlier allows local users to gain root privileges via a hard link attack on the Nagios init script file, related to CVE-2016-8641.

suse-cvrf
больше 7 лет назад

Security update for nagios

EPSS

Процентиль: 28%
0.00099
Низкий

6.7 Medium

CVSS3