CVE-2016-8641
Summary
| CVE | CVE-2016-8641 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-01 14:29:00 UTC |
| Updated | 2023-02-12 23:26:00 UTC |
| Description | A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Nagios 4.2.2 - Local Privilege Escalation - Linux local Exploit |
EXPLOIT-DB |
www.exploit-db.com |
Exploit, Third Party Advisory, VDB Entry |
| github.com/NagiosEnterprises/nagioscore/commit/f2ed227673d3b2da643eb5cad... |
CONFIRM |
github.com |
Patch, Third Party Advisory |
| 1394248 – (CVE-2016-8641) CVE-2016-8641 nagios: Unsafe ownership change leading to privilege escalation |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| Nagios CVE-2016-8641 Local Privilege Escalation Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Nagios: Multiple vulnerabilities (GLSA 201702-26) — Gentoo Security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710470 Gentoo Linux NagInternetwork Operating System Multiple Vulnerabilities (GLSA 201702-26)