CVE-2017-14312: High severity nagios vulnerability
Nagios Core through 4.3.4 initially executes /usr/sbin/nagios as root but supports configuration options in which this file is owned by a non-root account (and similarly can have nagios.cfg owned by a non-root account), which allows local users to gain privileges by leveraging access to this non-root account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14312?
CVE-2017-14312 is considered to have a medium severity due to its potential for privilege escalation.
How do I fix CVE-2017-14312?
To fix CVE-2017-14312, ensure that /usr/sbin/nagios and nagios.cfg are owned by the root account and have the appropriate file permissions.
Who is affected by CVE-2017-14312?
CVE-2017-14312 affects users running Nagios Core versions up to and including 4.3.4.
Can CVE-2017-14312 be exploited remotely?
CVE-2017-14312 is a local privilege escalation vulnerability and cannot be exploited remotely.
What versions of Nagios Core are vulnerable to CVE-2017-14312?
Nagios Core versions prior to 4.3.5 are vulnerable to CVE-2017-14312.