CVE-2012-3457: Low severity PNP4Nagios PNP4Nagios vulnerability
Published Aug 12, 2012
·Updated
PNP4Nagios 0.6 through 0.6.16 uses world-readable permissions for processperfdata.cfg, which allows local users to obtain the Gearman shared secret by reading the file.
Affected Software
15 affected components
PNP4Nagios PNP4Nagios=0.6.0
PNP4Nagios PNP4Nagios=0.6.1
PNP4Nagios PNP4Nagios=0.6.2
PNP4Nagios PNP4Nagios=0.6.3
PNP4Nagios PNP4Nagios=0.6.4
PNP4Nagios PNP4Nagios=0.6.5
PNP4Nagios PNP4Nagios=0.6.6
PNP4Nagios PNP4Nagios=0.6.7
PNP4Nagios PNP4Nagios=0.6.10
PNP4Nagios PNP4Nagios=0.6.11
PNP4Nagios PNP4Nagios=0.6.12
PNP4Nagios PNP4Nagios=0.6.13
PNP4Nagios PNP4Nagios=0.6.14
PNP4Nagios PNP4Nagios=0.6.15
PNP4Nagios PNP4Nagios=0.6.16
Event History
Aug 12, 2012
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3457?
CVE-2012-3457 has a moderate severity rating due to its potential to expose sensitive configuration data.
2
How do I fix CVE-2012-3457?
To fix CVE-2012-3457, you should change the permissions on process_perfdata.cfg to restrict access to authorized users only.
3
Which versions of PNP4Nagios are affected by CVE-2012-3457?
CVE-2012-3457 affects PNP4Nagios versions 0.6.0 through 0.6.16.
4
What type of vulnerability is CVE-2012-3457?
CVE-2012-3457 is a local privilege escalation vulnerability that allows unauthorized local users to read sensitive files.
5
How can CVE-2012-3457 impact my system?
CVE-2012-3457 can impact your system by allowing local users to access the Gearman shared secret, compromising system confidentiality.