Zurück zur CVE-Übersicht
CVE-2014-8994
LOW(3.6)AV:L/AC:L/Au:N/C:N/I:P/A:P
Risk Signal Score9/100 — NIEDRIG
EPSS-Score
0%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
3.6
Technische Schwere
Beschreibung
The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp/check_diskio_status-*-*).
Referenzen
- http://seclists.org/oss-sec/2014/q4/679
- http://seclists.org/oss-sec/2014/q4/701
- http://www.securityfocus.com/bid/71208
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98849
- http://seclists.org/oss-sec/2014/q4/679
- http://seclists.org/oss-sec/2014/q4/701
- http://www.securityfocus.com/bid/71208
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98849