Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-1549

Опубликовано: 30 мар. 2011
Источник: nvd
CVSS2: 6.3
EPSS Низкий

Описание

The default configuration of logrotate on Gentoo Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by directories under /var/log/ for packages.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:gentoo:logrotate:*:*:*:*:*:*:*:*
cpe:2.3:o:gentoo:linux:*:*:*:*:*:*:*:*

EPSS

Процентиль: 19%
0.00061
Низкий

6.3 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
почти 15 лет назад

The default configuration of logrotate on Gentoo Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by directories under /var/log/ for packages.

debian
почти 15 лет назад

The default configuration of logrotate on Gentoo Linux uses root privi ...

github
больше 3 лет назад

The default configuration of logrotate on Gentoo Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by directories under /var/log/ for packages.

fstec
больше 13 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 19%
0.00061
Низкий

6.3 Medium

CVSS2

Дефекты

CWE-264