CVE-2013-4214
Publication date 23 November 2013
Last updated 24 July 2024
Ubuntu priority
rss-newsfeed.php in Nagios Core 3.4.4, 3.5.1, and earlier, when MAGPIE_CACHE_ON is set to 1, allows local users to overwrite arbitrary files via a symlink attack on /tmp/magpie_cache.
Notes
mdeslaur
in html/rss-newsfeed.php and html/rss-corefeed.php removed completely by 80_dont_call_home.patch patch in trusty tmp file isn't actually used, as MAGPIE_CACHE_ON is set to 0 ignoring.