CVE-2016-8641

Source
https://cve.org/CVERecord?id=CVE-2016-8641
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-8641.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-8641
Downstream
Related
Published
2018-08-01T14:29:00Z
Modified
2026-07-08T12:28:58Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change.

References

Affected packages

Git / github.com/nagiosenterprises/nagioscore

Affected ranges

Type
GIT
Repo
https://github.com/nagiosenterprises/nagioscore
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:nagios:nagios:4.2.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:nagios:nagios:4.2.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:nagios:nagios:4.2.3:*:*:*:*:*:*:*",
        "cpe:2.3:a:nagios:nagios:4.2.2:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "4.2.0"
        },
        {
            "last_affected": "4.2.0"
        },
        {
            "introduced": "4.2.1"
        },
        {
            "last_affected": "4.2.1"
        },
        {
            "introduced": "4.2.3"
        },
        {
            "last_affected": "4.2.3"
        },
        {
            "introduced": "4.2.2"
        },
        {
            "last_affected": "4.2.2"
        }
    ],
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

4.*
4.2.0
4.2.1
4.2.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-8641.json"