vendor:
Nagios Plugins
by:
Dawid Golunski
N/A
CVSS
N/A
Arbitrary Option File Read
N/A
CWE
Product Name: Nagios Plugins
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2014
check_dhcp – Nagios Plugins <= 2.0.1 Arbitrary Option File Read
check_dhcp plugin that is a part of the official Nagios Plugins package contains a vulnerability that allows a malicious attacker to read parts of INI config files belonging to root on a local system. It could allow an attacker to obtain sensitive information like passwords that should only be accessible by root user. The vulnerability is due to check_dhcp plugin having Root SUID permissions and inappropriate access control when reading user provided files.
Mitigation:
N/A