Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3243

Опубликовано: 18 июн. 2015
Источник: redhat
CVSS2: 2.1

Описание

rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by reading files in /var/log/cron.

Отчет

This issue affects the versions of rsyslog as shipped with Red Hat Enterprise Linux 7. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/. Additionally a workaround is available (https://bugzilla.redhat.com/show_bug.cgi?id=1232826#c3).

Меры по смягчению последствий

Please add: create 0600 root root to the /etc/logrotate.d/syslog file, this will ensure the file is created with permissions when logrotate runs. It is also recommended that users manually set the permissions on existing or newly installed log files in order to prevent access by untrusted users.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5rsyslogNot affected
Red Hat Enterprise Linux 6rsyslogNot affected
Red Hat Enterprise Linux 7rsyslogAffected
Red Hat Storage 2rsyslogAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1188
https://bugzilla.redhat.com/show_bug.cgi?id=1232826rsyslog: some log files are created world-readable

2.1 Low

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 9 лет назад

rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by reading files in /var/log/cron.

CVSS3: 5.5
nvd
около 9 лет назад

rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by reading files in /var/log/cron.

CVSS3: 5.5
debian
около 9 лет назад

rsyslog uses weak permissions for generating log files, which allows l ...

suse-cvrf
около 8 лет назад

Security update for rsyslog

suse-cvrf
около 8 лет назад

Security update for rsyslog

2.1 Low

CVSS2