Bug 1517341 (CVE-2017-16834)

Summary: CVE-2017-16834 pnp4nagios: privilege escalation via insecure permissions
Product: [Other] Security Response Reporter: Adam Mariš <amaris>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: didier.fabert, rcyriac, sisharma, smohan, ssaha, vbellur, xavier
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-11-30 16:18:29 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1517344    
Bug Blocks: 1517347    

Description Adam Mariš 2017-11-24 15:59:56 UTC
PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account.

References:

https://github.com/lingej/pnp4nagios/issues/140
http://www.openwall.com/lists/oss-security/2017/11/16/1

Comment 1 Adam Mariš 2017-11-24 16:00:37 UTC
Created pnp4nagios tracking bugs for this issue:

Affects: epel-all [bug 1517344]

Comment 2 Siddharth Sharma 2017-11-30 16:18:29 UTC
Analysis:

spec file used to build this package for Red Hat Gluster Storage 3 contains following line:

sed -i -e 's/^INSTALL_OPTS="-o $nagios_user -g $nagios_grp"/INSTALL_OPTS=""/' \

which should remove 'nagios' as default user and group on further check it was observed 
1. /etc/pnp4nagios is owned by root
2. /usr/sbin/npcd is owned by root
3. /etc/pnp4nagios/nagios.cfg is owned by root

default 'nagios' user cannot edit /etc/pnp4nagios/nagios.cfg as its owned by root.