CVE-2016-10089: High severity Nagios nagios vulnerability
Published Feb 15, 2017
·Updated
Nagios 4.3.2 and earlier allows local users to gain root privileges via a hard link attack on the Nagios init script file, related to CVE-2016-8641.
Affected Software
1 affected component
Nagios nagios<=4.2.4
Event History
Feb 15, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-10089?
CVE-2016-10089 is rated as a high severity vulnerability due to the potential for local privilege escalation.
2
How does CVE-2016-10089 allow local users to gain root privileges?
CVE-2016-10089 allows local users to gain root privileges through a hard link attack on the Nagios init script file.
3
Which versions of Nagios are affected by CVE-2016-10089?
Nagios versions 4.3.2 and earlier are affected by CVE-2016-10089.
4
How do I fix CVE-2016-10089?
To fix CVE-2016-10089, users should upgrade Nagios to a version later than 4.3.2.
5
Is CVE-2016-10089 related to any other vulnerabilities?
CVE-2016-10089 is related to CVE-2016-8641, which also pertains to security issues in Nagios.