Lucene search

K
redhatRedHatRHSA-2017:0258
HistoryFeb 07, 2017 - 11:08 a.m.

(RHSA-2017:0258) Important: nagios security update

2017-02-0711:08:21
access.redhat.com
50

0.929 High

EPSS

Percentile

99.0%

Nagios is a program that monitors hosts and services on your network, and has the ability to send email or page alerts when a problem arises or is resolved.

Security Fix(es):

  • It was found that an attacker who could control the content of an RSS feed could execute code remotely using the Nagios web interface. This flaw could be used to gain access to the remote system and in some scenarios control over the system. (CVE-2016-9565)

  • A privilege escalation flaw was found in the way Nagios handled log files. An attacker able to control the Nagios logging configuration (the ‘nagios’ user/group) could use this flaw to elevate their privileges to root. (CVE-2016-9566)