Symlink attack in Nagios - CVE-2016-9566

 

Symlink attack in Nagios - CVE-2016-9566

Published: December 16, 2016


Vulnerability identifier: #VU1344
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2016-9566
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local user obtain elevated privileges on vulnerable system.

The vulnerability exists due to the application handles log files in unsafe manner. A local user with access to Nagios application (nagios account or member of nagios group) can cerate a specially crafted symlink to nagios log file and execute arbitrary command on vulnerable system with root privileges.

Successful exploitation of this vulnerability may allow a local user to obtain full access to vulnerable system.


Affected software

Nagios
Dell Secure Connect Gateway
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Manager Tools
Containers Module
Advanced Systems Management Module
SUSE Manager Client Tools Beta for SLE
SUSE Manager Client Tools for SLE
SUSE Linux Enterprise Server for the Raspberry Pi
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Workstation Extension 12
hwdata
grafana-sap-netweaver-dashboards
grafana-sleha-provider
grafana-ha-cluster-dashboards
grafana-sap-providers
icinga-debuginfo
icinga
monitoring-tools
icinga-www-config
icinga-www
icinga-plugins-downtimes
icinga-debugsource
icinga-devel
icinga-doc
icinga-idoutils
icinga-idoutils-mysql
icinga-idoutils-oracle
icinga-idoutils-pgsql
icinga-plugins-eventhandlers
sysuser-shadow
sysuser-tools
zeromq-debugsource
libzmq3
libzmq3-debuginfo
zeromq-devel

How to mitigate CVE-2016-9566

Install the latest version 4.2.4, which fixes the vulnerability.

hwdata - update to 0.314-10.14.1
grafana-sap-netweaver-dashboards - update to 1.0.3+git.1601889366.9f71957-1.10.1
grafana-sleha-provider - update to 1.1.0+git.1605027022.a84d536-1.10.1
grafana-ha-cluster-dashboards - update to 1.1.0+git.1605027022.a84d536-1.10.1
grafana-sap-providers - update to 1.1-1.7.1
icinga-debuginfo - addressed in versions 1.13.3-12.6.1, 1.13.3-12.8.1
icinga - addressed in versions 1.13.3-12.6.1, 1.13.3-12.8.1
monitoring-tools - addressed in versions 1.13.3-12.6.1, 1.13.3-12.8.1
icinga-www-config - addressed in versions 1.13.3-12.6.1, 1.13.3-12.8.1
icinga-www - addressed in versions 1.13.3-12.6.1, 1.13.3-12.8.1
icinga-plugins-downtimes - addressed in versions 1.13.3-12.6.1, 1.13.3-12.8.1
icinga-debugsource - addressed in versions 1.13.3-12.6.1, 1.13.3-12.8.1
icinga-devel - addressed in versions 1.13.3-12.6.1, 1.13.3-12.8.1
icinga-doc - addressed in versions 1.13.3-12.6.1, 1.13.3-12.8.1
icinga-idoutils - addressed in versions 1.13.3-12.6.1, 1.13.3-12.8.1
icinga-idoutils-mysql - addressed in versions 1.13.3-12.6.1, 1.13.3-12.8.1
icinga-idoutils-oracle - addressed in versions 1.13.3-12.6.1, 1.13.3-12.8.1
icinga-idoutils-pgsql - addressed in versions 1.13.3-12.6.1, 1.13.3-12.8.1
icinga-plugins-eventhandlers - addressed in versions 1.13.3-12.6.1, 1.13.3-12.8.1
sysuser-shadow - update to 2.0-1.9.1
sysuser-tools - update to 2.0-1.9.1
zeromq-debugsource - update to 4.0.4-15.8.1
libzmq3 - update to 4.0.4-15.8.1
libzmq3-debuginfo - update to 4.0.4-15.8.1
zeromq-devel - update to 4.0.4-15.8.1
Dell Secure Connect Gateway - update to 5.24.00.14

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins