Icinga: Privilege escalation — GLSA 201612-51

A vulnerability in Icinga could lead to privilege escalation.

Affected packages

net-analyzer/icinga on all architectures
Affected versions < 1.13.4
Unaffected versions >= 1.13.4

Background

Icinga is an open source computer system and network monitoring application. It was originally created as a fork of the Nagios system monitoring application in 2009.

Description

Icinga daemon was found to perform unsafe operations when handling the log file.

Impact

A local attacker, who either is already Icinga’s system user or belongs to Icinga’s group, could potentially escalate privileges.

Workaround

There is no known workaround at this time.

Resolution

All Icinga users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-analyzer/icinga-1.13.4"
 

References

Release date
December 31, 2016

Latest revision
December 31, 2016: 1

Severity
normal

Exploitable
local

Bugzilla entries