PublicDateAtUSN: 2016-12-15 Candidate: CVE-2016-9566 PublicDate: 2016-12-15 22:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9566 https://ubuntu.com/security/notices/USN-3253-1 Description: base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Dawid Golunski Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_nagios3: upstream: https://github.com/NagiosEnterprises/nagioscore/commit/c29557dec91eba2306f5fb11b8da4474ba63f8c4 upstream_nagios3: needs-triage precise_nagios3: ignored (reached end-of-life) precise/esm_nagios3: DNE (precise was needed) trusty_nagios3: released (3.5.1-1ubuntu1.1) trusty/esm_nagios3: DNE (trusty was released [3.5.1-1ubuntu1.1]) vivid/stable-phone-overlay_nagios3: DNE vivid/ubuntu-core_nagios3: DNE xenial_nagios3: released (3.5.1.dfsg-2.1ubuntu1.1) esm-infra/xenial_nagios3: released (3.5.1.dfsg-2.1ubuntu1.1) yakkety_nagios3: released (3.5.1.dfsg-2.1ubuntu3.1) zesty_nagios3: released (3.5.1.dfsg-2.1ubuntu5) devel_nagios3: released (3.5.1.dfsg-2.1ubuntu5)