|
|||
Rule General Information |
---|
Release Date: | 2017-05-15 | |
Rule Name: | Nagios Local Privilege Escalation Vulnerability (CVE-2016-9566) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. | |
Impact: | An attacker can abtain more privileges which he is not entitled to by exloiting the vulnerability, such as executing arbitrary code, deleting files, viewing sensitive information, changing configurations. | |
Affected OS: | Other Unix, FreeBSD, Linux | |
Reference: | SecurityFocusBID:94919 SecurityTrackerID:1037487 |
|
Solutions |
---|
Upgrade to version 4.2.4 to solve the problem. |