5.5
CVSSv3

CVE-2018-6536

CVSSv4: NA | CVSSv3: 5.5 | CVSSv2: 4.9 | VMScore: 650 | EPSS: 0.00042 | KEV: Not Included
Published: 02/02/2018 Updated: 21/11/2024

Vulnerability Summary

An issue exists in Icinga 2.x up to and including 2.8.1. The daemon creates an icinga2.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for icinga2.pid modification before a root script executes a "kill `cat /pathname/icinga2.pid`" command, as demonstrated by icinga2.init.d.cmake.

Vulnerable Product Search on Vulmon Subscribe to Product

icinga icinga

Vendor Advisories

Debian Bug report logs - #883247 CVE-2017-16933: icinga2: root privilege escalation via prepare-dirs Package: icinga2; Maintainer for icinga2 is Debian Nagios Maintainer Group <pkg-nagios-devel@listsaliothdebianorg>; Source for icinga2 is src:icinga2 (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Da ...
Debian Bug report logs - #897301 CVE-2018-6532 CVE-2018-6534 CVE-2018-6535 Package: src:icinga2; Maintainer for src:icinga2 is Debian Nagios Maintainer Group <pkg-nagios-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 1 May 2018 10:12:08 UTC Severity: important Tags: secur ...