Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3243

Опубликовано: 18 июн. 2015
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by reading files in /var/log/cron.

Отчет

This issue affects the versions of rsyslog as shipped with Red Hat Enterprise Linux 7. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/. Additionally a workaround is available (https://bugzilla.redhat.com/show_bug.cgi?id=1232826#c3).

Меры по смягчению последствий

Please add: create 0600 root root to the /etc/logrotate.d/syslog file, this will ensure the file is created with permissions when logrotate runs. It is also recommended that users manually set the permissions on existing or newly installed log files in order to prevent access by untrusted users.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5rsyslogNot affected
Red Hat Enterprise Linux 6rsyslogNot affected
Red Hat Enterprise Linux 7rsyslogAffected
Red Hat Storage 2.1rsyslogAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-732->CWE-532
https://bugzilla.redhat.com/show_bug.cgi?id=1232826rsyslog: some log files are created world-readable

EPSS

Процентиль: 33%
0.00134
Низкий

2.1 Low

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by reading files in /var/log/cron.

CVSS3: 5.5
nvd
больше 8 лет назад

rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by reading files in /var/log/cron.

CVSS3: 5.5
debian
больше 8 лет назад

rsyslog uses weak permissions for generating log files, which allows l ...

suse-cvrf
больше 7 лет назад

Security update for rsyslog

suse-cvrf
больше 7 лет назад

Security update for rsyslog

EPSS

Процентиль: 33%
0.00134
Низкий

2.1 Low

CVSS2