CVE-2016-8641

Description

A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. Its possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.839

Associated Vulnerability

VulnerabilityOS Platform
SUSE-SU-2018:3240-1(SUSE Linux Enterprise Server 11-SP4 ) nagios-3.0.6-1.25.36.3.1.i586.rpmLinux
SUSE-SU-2018:3240-1(SUSE Linux Enterprise Server 11-SP4 ) nagios-3.0.6-1.25.36.3.1.x86_64.rpmLinux
SUSE-SU-2018:3240-1(SUSE Linux Enterprise Server 11-SP4 ) nagios-www-3.0.6-1.25.36.3.1.i586.rpmLinux
SUSE-SU-2018:3240-1(SUSE Linux Enterprise Server 11-SP4 ) nagios-www-3.0.6-1.25.36.3.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234