Vulnerability CVE-2016-8641


Published: 2018-08-01

Description:
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change.

Type:

CWE-59

(Improper Link Resolution Before File Access ('Link Following'))

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.2/10
10/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Nagios -> Nagios 

 References:
http://www.securityfocus.com/bid/95121
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8641
https://github.com/NagiosEnterprises/nagioscore/commit/f2ed227673d3b2da643eb5cad26b2d87674f28c1.patch
https://security.gentoo.org/glsa/201702-26
https://www.exploit-db.com/exploits/40774/

Copyright 2024, cxsecurity.com

 

Back to Top