Security Advisory
CVE-2014-8994
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp/check_diskio_status-*-*).