CVE-2013-2029
published 2013-11-23CVE-2013-2029: nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arbitrary…
PriorityP420medium6.3CVSS 2.0
AVLACMAuNCNICAC
EPSS
0.35%
27.5th percentile
nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arbitrary files via a symlink attack on a temporary nagioscfg file with a predictable name in /tmp/.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openstack | — | — |
CVSS provenance
nvdv2.06.3MEDIUMAV:L/AC:M/Au:N/C:N/I:C/A:C
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
core: Insecure temporary file usage in nagios.upgrade_to_v3.sh
vendor_redhat·2013-04-30·CVSS 6.3
CVE-2013-2029 [MEDIUM] CWE-377 core: Insecure temporary file usage in nagios.upgrade_to_v3.sh
core: Insecure temporary file usage in nagios.upgrade_to_v3.sh
nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arbitrary files via a symlink attack on a temporary nagioscfg file with a predictable name in /tmp/.
Statement: The Red Hat Security Response Team has rated this issue as having moderate security impact. This issue is not currently planned to be addressed in OpenStack 2.1 (Folsom). For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: nagios (Red Hat OpenStack Platform 4) - Affected
GHSA
GHSA-8727-34w8-v299: nagios
ghsa_unreviewed·2022-05-17
CVE-2013-2029 [MEDIUM] CWE-59 GHSA-8727-34w8-v299: nagios
nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arbitrary files via a symlink attack on a temporary nagioscfg file with a predictable name in /tmp/.
No detection rules found.
No public exploits indexed.
2013-11-23
Published