ZeroHour

CVE-2016-9566

PoC
CVSS 3.0
7.8 high
EPSS
5%p92
Published
()
Modified
Description

base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.

Vendors
nagios
Products
nagios
Weakness
CWE-59, CWE-264
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news