Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-1548

Опубликовано: 30 мар. 2011
Источник: nvd
CVSS2: 6.3
EPSS Низкий

Описание

The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by /var/log/postgresql/.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:gentoo:logrotate:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:linux:*:*:*:*:*:*:*:*

EPSS

Процентиль: 19%
0.00059
Низкий

6.3 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
почти 15 лет назад

The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by /var/log/postgresql/.

debian
почти 15 лет назад

The default configuration of logrotate on Debian GNU/Linux uses root p ...

github
больше 3 лет назад

The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by /var/log/postgresql/.

EPSS

Процентиль: 19%
0.00059
Низкий

6.3 Medium

CVSS2

Дефекты

CWE-264