CVE-2016-9566
Beschrijving NL
base/logging.c in Nagios Core vóór 4.2.4 stelt lokale gebruikers met toegang tot een account in de nagios-groep in staat om rootprivileges te verkrijgen via een symlink-aanval op het logboekbestand. OPMERKING: dit kan worden gebruikt door externe aanvallers met behulp van CVE-2016-9565.
Origineel (Engels) tonen
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.
Vendors
Affected products
References
- rhn.redhat.com
- rhn.redhat.com
- rhn.redhat.com
- rhn.redhat.com
- rhn.redhat.com
- rhn.redhat.com
- seclists.org
- www.securityfocus.com
- www.securitytracker.com
- bugzilla.redhat.com
- github.com
- legalhackers.com
- lists.debian.org
- security.gentoo.org
- security.gentoo.org
- security.gentoo.org
- www.exploit-db.com
- www.nagios.org