rss-newsfeed.php in Nagios Core 3.4.4, 3.5.1, and earlier, when MAGPIE_CACHE_ON is set to 1, allows local users to overwrite arbitrary files via a symlink attack on /tmp/magpie_cache.
2013-11-23T17:55:03.430
2025-04-11T00:51:21.963
Deferred
CVSSv2: 6.3 (MEDIUM)
AV:L/AC:M/Au:N/C:N/I:C/A:C
3.4
9.2
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nagios | nagios | ≤ 3.5.1 | Yes |
Application | nagios | nagios | 3.4.4 | Yes |
Application | redhat | openstack | 3.0 | Yes |