[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-6536 -- icinga2

ID: oval:org.secpod.oval:def:2000433Date: (C)2019-04-22   (M)2021-06-02
Class: VULNERABILITYFamily: unix




An issue was discovered in Icinga 2.x through 2.8.1. The daemon creates an icinga2.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for icinga2.pid modification before a root script executes a "kill `cat /pathname/icinga2.pid`" command, as demonstrated by icinga2.init.d.cmake.

Platform:
Debian 8.x
Debian 9.x
Product:
icinga2
Reference:
CVE-2018-6536
CVE    1
CVE-2018-6536
CPE    3
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:9.x
cpe:/a:icinga:icinga2

© SecPod Technologies