Werk #16249: mk_informix: Follow up for Werk 16198
Component | Checks & agents | ||||||||
Title | mk_informix: Follow up for Werk 16198 | ||||||||
Date | Jul 26, 2024 | ||||||||
Level | Trivial Change | ||||||||
Class | Security Fix | ||||||||
Compatibility | Compatible - no manual interaction needed | ||||||||
Checkmk versions & editions |
|
Werk #16198 addressed potential priviledge escalation by the agent plugin mk_informix
.
However, a few callsites to the binaries dbaccess
and onstat
where missing the safe execution.
Those binaries are now also called in a safe way.
Vulnerability Management:
We have rated the issue with a CVSS Score of 5.2 (Medium) with the following CVSS vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H
and assigned CVE CVE-2024-28829
.