Описание
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.
A privilege escalation flaw was found in the way Nagios handled log files. An attacker able to control the Nagios logging configuration (the 'nagios' user/group) could use this flaw to elevate their privileges to root.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Mobile Application Platform 4 | nagios | Affected | ||
| Red Hat OpenStack Platform 10 (Newton) | nagios | Not affected | ||
| Red Hat OpenStack Platform 8 (Liberty) | nagios | Not affected | ||
| Red Hat OpenStack Platform 9 (Mitaka) | nagios | Not affected | ||
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | nagios | Fixed | RHSA-2017:0212 | 31.01.2017 |
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 | nagios | Fixed | RHSA-2017:0211 | 31.01.2017 |
| Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | nagios | Fixed | RHSA-2017:0213 | 31.01.2017 |
| Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 | nagios | Fixed | RHSA-2017:0214 | 31.01.2017 |
| Red Hat Gluster Storage 3.1 for RHEL 6 | nagios | Fixed | RHSA-2017:0259 | 07.02.2017 |
| Red Hat Gluster Storage 3.1 for RHEL 7 | nagios | Fixed | RHSA-2017:0258 | 07.02.2017 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.3 High
CVSS3
6.9 Medium
CVSS2
Связанные уязвимости
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.
base/logging.c in Nagios Core before 4.2.4 allows local users with acc ...
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.
EPSS
7.3 High
CVSS3
6.9 Medium
CVSS2