cvelist/2017/16xxx/CVE-2017-16834.json

67 lines
2.0 KiB
JSON
Raw Normal View History

2017-11-15 20:03:42 -05:00
{
2019-03-18 03:39:20 +00:00
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2017-16834",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
2017-11-15 21:03:11 -05:00
{
2019-03-18 03:39:20 +00:00
"lang": "eng",
"value": "PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account."
2017-11-15 21:03:11 -05:00
}
2019-03-18 03:39:20 +00:00
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "GLSA-201806-09",
"refsource": "GENTOO",
"url": "https://security.gentoo.org/glsa/201806-09"
},
{
"name": "https://github.com/lingej/pnp4nagios/issues/140",
"refsource": "MISC",
"url": "https://github.com/lingej/pnp4nagios/issues/140"
}
]
}
}