CVE-2016-9566
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.
- Affected products
- Alt Linux, Nagios Core, Suse, Ubuntu
- Nagios
- ≤ 4.2.3
- Fix
- Available
- CVSS 3.0
- 7.8 HIGH
- EPSS
- 4.9% (91th percentile)
- Weakness
- CWE-264, CWE-59
- NVD status
- Modified
- Published
- 2016-12-15
CVE-2016-9566 at NVD
8 known exploits for CVE-2016-9566
Proof-of-concept code and exploit modules indexed by Sploitus
Nagios 4.2.2 - Arbitrary Code Execution Exploit
Nagios 4.2.4 - Privilege Escalation Exploit
Nagios Core < 4.2.4 - Root Privilege Escalation (CVE-2016-9566)
Nagios 4.2.4 - Local Privilege Escalation
Nagios 4.2.2 - Arbitrary Code Execution
Nagios < 4.2.2 - Arbitrary Code Execution
Nagios < 4.2.4 - Local Privilege Escalation
Nagios Core Curl Command Injection / Code Execution