PT-2011-2282 · Balabit · Syslog-Ng

Steven Chamberlain

·

Publicado

2011-01-28

·

Atualizado

2020-05-19

·

CVE-2011-0343

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Balabit syslog-ng versions 2.0, 3.0, 3.1, 3.2 OSE and PE
Description The issue is related to improper cast operations when running on certain operating systems, resulting in the creation of log files with insecure permissions. This allows local users to read and write to these log files.
Recommendations For Balabit syslog-ng versions 2.0, 3.0, 3.1, 3.2 OSE and PE, consider changing the default permissions to a more secure setting to prevent unauthorized access to log files.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-0343
OPENSUSE-SU-2024:10493-1

Produtos afetados

Syslog-Ng