CVE Vulnerabilities

CVE-2014-8994

Published: Nov 28, 2014 | Modified: Sep 08, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp/check_diskio_status--).

Affected Software

Name Vendor Start Version End Version
Check_diskio Check_diskio_project * 3.2.5 (including)

References