![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2017-14312 |
Description: | Nagios Core through 4.3.4 initially executes /usr/sbin/nagios as root but supports configuration options in which this file is owned by a non-root account (and similarly can have nagios.cfg owned by a non- root account), which allows local users to gain privileges by leveraging access to this non-root account. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.140375 1.3.6.1.4.1.25623.1.0.873744 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2017-14312 BugTraq ID: 100881 http://www.securityfocus.com/bid/100881 https://security.gentoo.org/glsa/201812-03 https://github.com/NagiosEnterprises/nagioscore/issues/424 |