Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-1550

Опубликовано: 30 мар. 2011
Источник: nvd
CVSS2: 6.3
EPSS Низкий

Описание

The default configuration of logrotate on SUSE openSUSE Factory uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by directories for the (1) cobbler, (2) inn, (3) safte-monitor, and (4) uucp packages.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:gentoo:logrotate:*:*:*:*:*:*:*:*
cpe:2.3:o:novell:opensuse_factory:*:*:*:*:*:*:*:*

EPSS

Процентиль: 14%
0.00045
Низкий

6.3 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
почти 15 лет назад

The default configuration of logrotate on SUSE openSUSE Factory uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by directories for the (1) cobbler, (2) inn, (3) safte-monitor, and (4) uucp packages.

debian
почти 15 лет назад

The default configuration of logrotate on SUSE openSUSE Factory uses r ...

github
больше 3 лет назад

The default configuration of logrotate on SUSE openSUSE Factory uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by directories for the (1) cobbler, (2) inn, (3) safte-monitor, and (4) uucp packages.

EPSS

Процентиль: 14%
0.00045
Низкий

6.3 Medium

CVSS2

Дефекты

CWE-264