PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-11-16T02:00:00.000Z

Updated: 2024-08-05T20:35:21.009Z

Reserved: 2017-11-15T00:00:00.000Z

Link: CVE-2017-16834

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-11-16T02:29:05.410

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-16834

cve-icon Redhat

Severity : Moderate

Publid Date: 2017-11-15T00:00:00Z

Links: CVE-2017-16834 - Bugzilla