CVE-2014-8994 Information

Description

The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp/check_diskio_status--).

Reference

http://seclists.org/oss-sec/2014/q4/679 http://seclists.org/oss-sec/2014/q4/701 http://www.securityfocus.com/bid/71208 https://exchange.xforce.ibmcloud.com/vulnerabilities/98849

Share on: