RULE(RULE ID:711153)

Rule General Information
Release Date: 2017-05-15
Rule Name: Nagios Local Privilege Escalation Vulnerability (CVE-2016-9566)
Severity:
CVE ID:
Rule Protection Details
Description: base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file.
Impact: An attacker can abtain more privileges which he is not entitled to by exloiting the vulnerability, such as executing arbitrary code, deleting files, viewing sensitive information, changing configurations.
Affected OS: Other Unix, FreeBSD, Linux
Reference: SecurityFocusBID:94919
SecurityTrackerID:1037487
Solutions
Upgrade to version 4.2.4 to solve the problem.