A vulnerability in Icinga could lead to privilege escalation.
Package | net-analyzer/icinga on all architectures |
---|---|
Affected versions | < 1.13.4 |
Unaffected versions | >= 1.13.4 |
Icinga is an open source computer system and network monitoring application. It was originally created as a fork of the Nagios system monitoring application in 2009.
Icinga daemon was found to perform unsafe operations when handling the log file.
A local attacker, who either is already Icinga’s system user or belongs to Icinga’s group, could potentially escalate privileges.
There is no known workaround at this time.
All Icinga users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=net-analyzer/icinga-1.13.4"
Release date
December 31, 2016
Latest revision
December 31, 2016: 1
Severity
normal
Exploitable
local
Bugzilla entries