The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp/check_diskio_status-*-*).
This entry has been deprecated. It was originally used for organizing the Development View (CWE-699) and some other views, but it introduced unnecessary complexity and depth to the resulting tree.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/98849 | vdb entry |
http://www.securityfocus.com/bid/71208 | vdb entry |
http://seclists.org/oss-sec/2014/q4/679 | mailing list |
http://seclists.org/oss-sec/2014/q4/701 | mailing list |