VYPR
High severity7.8NVD Advisory· Published Nov 18, 2017· Updated May 13, 2026

CVE-2017-16882

CVE-2017-16882

Description

Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-root account (and similarly can have etc/icinga.cfg owned by a non-root account), which allows local users to gain privileges by leveraging access to this non-root account, a related issue to CVE-2017-14312. This also affects bin/icingastats, bin/ido2db, and bin/log2ido.

Affected products

1
  • cpe:2.3:a:icinga:icinga:*:*:*:*:*:*:*:*
    Range: <=1.14.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.