CVE-2017-16834

Publication date 16 November 2017

Last updated 17 July 2025


Ubuntu priority

Cvss 3 Severity Score

7.8 · High

Score breakdown

Description

PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account.

Read the notes from the security team

Status

Package Ubuntu Release Status
pnp4nagios 18.10 cosmic Not in release
18.04 LTS bionic Not in release
17.10 artful Not in release
17.04 zesty Not in release
16.04 LTS xenial Not in release
14.04 LTS trusty Not in release

Notes


msalvatore

/etc/pnp4nagios and npcd binary are already owned by root.

Severity score breakdown

CVSS version: CVSS v3.0

Base score 7.8 · High

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H


Access our resources on patching vulnerabilities