{"id":"CVE-2017-12847","details":"Nagios Core before 4.3.3 creates a nagios.lock PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for nagios.lock modification before a root script executes a \"kill `cat /pathname/nagios.lock`\" command.","modified":"2026-05-07T21:09:33.644177Z","published":"2017-08-23T21:29:00.200Z","related":["openSUSE-SU-2024:11073-1"],"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/100403"},{"type":"ADVISORY","url":"https://github.com/NagiosEnterprises/nagioscore/blob/master/Changelog"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201710-20"},{"type":"REPORT","url":"https://github.com/NagiosEnterprises/nagioscore/issues/404"},{"type":"FIX","url":"https://github.com/NagiosEnterprises/nagioscore/commit/1b197346d490df2e2d3b1dcce5ac6134ad0c8752"},{"type":"FIX","url":"https://github.com/NagiosEnterprises/nagioscore/commit/3baffa78bafebbbdf9f448890ba5a952ea2d73cb"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nagiosenterprises/nagioscore","events":[{"introduced":"0"},{"last_affected":"0d44707a60d6c91948bc4386ce83cfcf8084bf5d"}],"database_specific":{"cpe":"cpe:2.3:a:nagios:nagios:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"4.3.2"}],"source":"CPE_FIELD"}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-12847.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"}]}