CVE-2016-9566: High severity nagios plugins vulnerability
An unsafe file opening/creation of logging files that can be misused for root privilege escalation was found in base/logging.c.
Upstream patch:
https://github.com/NagiosEnterprises/nagioscore/commit/c29557dec91eba2306f5fb11b8da4474ba63f8c4
Other sources
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9566?
CVE-2016-9566 is considered a critical vulnerability due to the potential for root privilege escalation.
How do I fix CVE-2016-9566?
To fix CVE-2016-9566, you should update Nagios to version 4.2.4 or later.
What software is affected by CVE-2016-9566?
CVE-2016-9566 affects Nagios versions up to 4.2.3 and below.
Can CVE-2016-9566 be exploited remotely?
Yes, CVE-2016-9566 can potentially be exploited remotely if the logging functionality is accessible.
What type of vulnerability is CVE-2016-9566?
CVE-2016-9566 is an unsafe file opening vulnerability that can lead to privilege escalation.