CVE Database
/

CVE-2016-9566

Back to search

CVE-2016-9566

Published: Dec 15, 2016

Modified: Aug 6, 2024

PUBLISHED

Description

base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.

VendorProductVersions

n/a

n/a

affected
n/a

References

GLSA-201710-20
vendor-advisory
x_refsource_GENTOO
40921
exploit
x_refsource_EXPLOIT-DB
94919
vdb-entry
x_refsource_BID
RHSA-2017:0258
vendor-advisory
x_refsource_REDHAT
GLSA-201612-51
vendor-advisory
x_refsource_GENTOO
RHSA-2017:0212
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0213
vendor-advisory
x_refsource_REDHAT
GLSA-201702-26
vendor-advisory
x_refsource_GENTOO
RHSA-2017:0259
vendor-advisory
x_refsource_REDHAT
1037487
vdb-entry
x_refsource_SECTRACK
RHSA-2017:0214
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0211
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now