From de49812990871e1705b64051c35161d5e6400269 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Mon, 24 Dec 2018 14:11:38 +0000 Subject: gentoo resync : 24.12.2018 --- metadata/glsa/glsa-201812-03.xml | 48 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 48 insertions(+) create mode 100644 metadata/glsa/glsa-201812-03.xml (limited to 'metadata/glsa/glsa-201812-03.xml') diff --git a/metadata/glsa/glsa-201812-03.xml b/metadata/glsa/glsa-201812-03.xml new file mode 100644 index 000000000000..859d27b0cf4a --- /dev/null +++ b/metadata/glsa/glsa-201812-03.xml @@ -0,0 +1,48 @@ + + + + Nagios: Privilege escalation + A vulnerability in Nagios allows local users to escalate + privileges. + + nagios + 2018-12-02 + 2018-12-02 + 629380 + local + + + 4.3.4 + 4.3.4 + + + +

Nagios is an open source host, service and network monitoring program.

+
+ +

A vulnerability in Nagios was discovered due to the improper handling of + configuration files which can be owned by a non-root user. +

+
+ +

A local attacker can escalate privileges to root by leveraging access to + a non-root owned configuration file. +

+
+ +

There is no known workaround at this time.

+
+ +

All Nagios users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-analyzer/nagios-core-4.3.4" + +
+ + CVE-2017-14312 + + b-man + b-man +
-- cgit v1.2.3