Security Advisory

CVE-2013-2029

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2013-11-23 17:00:00
Last updated 2024-08-06 15:20:37
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arbitrary files via a symlink attack on a temporary nagioscfg file with a predictable name in /tmp/.