47
CVE-2016-9566
PoC —CVSS 3.0
7.8 high
EPSS
5%p92
Published
()
Modified
Description
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.
- Vendors
- nagios
- Products
- nagios
- Weakness
- CWE-59, CWE-264
- Vector
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H