Where
-Infinity
0
Severity
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned by the nagios user.

First published (updated )

Couldn't think of a better place to ask this. I requested a CVE back in March for an issue with the installed permissions in Nagios's NDOUtils. I think the request ID was #1620090.

I received a confirmation, but never got a follow-up response. I've since replied to the CVE-Request@ address, and have filled out the form with an "other" request asking for an update, but haven't heard back. New requests are obviously still being issued -- is there some way to find out what happened to this one?

FWIW:

Before NDOUtils-2.1.4 (released five days ago), the upstream Makefile would install the "ndo2db" daemon executable with the same owner/group that it is intended eventually to run as (namely: "nagios"). But the daemon is designed to be started as root and drop privileges to that user. If the "nagios" user can edit a binary that root will run, he can gain root privileges.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203