The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp/check_diskio_status-*-*).
References
Configurations
Information
Published : 2014-11-28 07:59
Updated : 2017-09-07 18:29
NVD link : CVE-2014-8994
Mitre link : CVE-2014-8994
JSON object : View
CWE
CWE-18
DEPRECATED: Source Code
Products Affected
check_diskio_project
- check_diskio