Icinga: Privilege escalation A vulnerability in Icinga could lead to privilege escalation. icinga December 31, 2016 December 31, 2016: 1 603534 local 1.13.4 1.13.4

Icinga is an open source computer system and network monitoring application. It was originally created as a fork of the Nagios system monitoring application in 2009.

Icinga daemon was found to perform unsafe operations when handling the log file.

A local attacker, who either is already Icinga’s system user or belongs to Icinga’s group, could potentially escalate privileges.

There is no known workaround at this time.

All Icinga users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-analyzer/icinga-1.13.4"
CVE-2016-9566 whissi whissi