CVE-2017-14312
11.09.2017, 22:29
Nagios Core through 4.3.4 initially executes /usr/sbin/nagios as root but supports configuration options in which this file is owned by a non-root account (and similarly can have nagios.cfg owned by a non-root account), which allows local users to gain privileges by leveraging access to this non-root account.Enginsight
Vendor | Product | Version |
---|---|---|
nagios | nagios_core | 𝑥 ≤ 4.3.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration