Bug 1394248 (CVE-2016-8641)

Summary: CVE-2016-8641 nagios: Unsafe ownership change leading to privilege escalation
Product: [Other] Security Response Reporter: Adam Mariš <amaris>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aortega, apevec, avibelli, ayoung, carnil, chrisw, coneill, cvsbot-xmlrpc, gsterlin, jbalunas, jschluet, jshepherd, kbasil, lhh, lpeer, markmc, mmagr, rbryant, rrajasek, sclewis, security-response-team, sgirijan, sisharma, smohan, srevivo, ssaha, tdecacqu, tjay, tkirby, tsuter, vbellur
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-01-19 06:21:43 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1397175    
Bug Blocks: 1394253, 1397646    

Description Adam Mariš 2016-11-11 13:25:35 UTC
A privilege escalation vulnerability was found in nagios that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change.

Upstream patch:

https://github.com/NagiosEnterprises/nagioscore/commit/f2ed227673d3b2da643eb5cad26b2d87674f28c1.patch

Comment 1 Adam Mariš 2016-11-11 13:25:54 UTC
Acknowledgments:

Name: Vincent Malguy

Comment 3 Tim Suter 2017-01-19 06:20:16 UTC
Statement:

Red Hat OpenStack Platform versions 5, 6 and 7 are now in Phase 2 of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat OpenStack Platform Life Cycle: https://access.redhat.com/support/policy/updates/openstack/platform/