CVE-2017-16933: High severity Icinga Icinga vulnerability
Published Nov 24, 2017
·Updated
etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gain privileges by leveraging access to the $ICINGA2USER account for creation of a link.
Affected Software
1 affected component
Icinga Icinga>=2.0.0<=2.8.0
Event History
Nov 24, 2017
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-16933.
2
What is the severity of CVE-2017-16933?
The severity of CVE-2017-16933 is high.
3
Which software versions are affected by CVE-2017-16933?
CVE-2017-16933 affects Icinga 2.x versions from 2.0.0 to 2.8.0.
4
How does CVE-2017-16933 allow local users to gain privileges?
CVE-2017-16933 allows local users to gain privileges by leveraging access to the $ICINGA2_USER account for creation of a link.
5
Is there a fix available for CVE-2017-16933?
Yes, users should update to Icinga 2.x version 2.8.1 or later to fix the vulnerability.