7
CVSSv3

CVE-2017-16933

Published: 24/11/2017 Updated: 03/10/2019
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

etc/initsystem/prepare-dirs in Icinga 2.x up to and including 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gain privileges by leveraging access to the $ICINGA2_USER account for creation of a link.

Vulnerable Product Search on Vulmon Subscribe to Product

icinga icinga

Vendor Advisories

Debian Bug report logs - #883247 CVE-2017-16933: icinga2: root privilege escalation via prepare-dirs Package: icinga2; Maintainer for icinga2 is Debian Nagios Maintainer Group <pkg-nagios-devel@listsaliothdebianorg>; Source for icinga2 is src:icinga2 (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Da ...
Debian Bug report logs - #897301 CVE-2018-6532 CVE-2018-6534 CVE-2018-6535 Package: src:icinga2; Maintainer for src:icinga2 is Debian Nagios Maintainer Group <pkg-nagios-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 1 May 2018 10:12:08 UTC Severity: important Tags: secur ...