CVE-2011-0343
Published Jan 28, 2011
Last updated 4 years ago
Overview
- Description
- Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes syslog-ng to use a default value of -1 to create log files with insecure permissions (07777), which allows local users to read and write to these log files.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.9
- Impact score
- 10
- Exploitability score
- 3.4
- Vector string
- AV:L/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:oneidentity:syslog-ng:2.0:*:*:*:open_source:*:*:*", "vulnerable": true, "matchCriteriaId": "AA602F56-CDB9-42CF-B0EB-EA74A5FF5B2C" }, { "criteria": "cpe:2.3:a:oneidentity:syslog-ng:2.0:*:*:*:premium:*:*:*", "vulnerable": true, "matchCriteriaId": "38AA2F0D-C28E-41C1-A633-739E27C2FB34" }, { "criteria": "cpe:2.3:a:oneidentity:syslog-ng:3.0:*:*:*:open_source:*:*:*", "vulnerable": true, "matchCriteriaId": "FFA1DF8D-21B7-4C55-B801-E7EC3F52F17E" }, { "criteria": "cpe:2.3:a:oneidentity:syslog-ng:3.0:*:*:*:premium:*:*:*", "vulnerable": true, "matchCriteriaId": "59A4D408-6519-422A-9AFB-FFF4A35E2265" }, { "criteria": "cpe:2.3:a:oneidentity:syslog-ng:3.1:*:*:*:open_source:*:*:*", "vulnerable": true, "matchCriteriaId": "A4D0AFDC-381A-4F64-89B3-E1025E786AE0" }, { "criteria": "cpe:2.3:a:oneidentity:syslog-ng:3.1:*:*:*:premium:*:*:*", "vulnerable": true, "matchCriteriaId": "05651F7F-AC3D-43E8-AD9B-317E9BC0C2D5" }, { "criteria": "cpe:2.3:a:oneidentity:syslog-ng:3.2:*:*:*:open_source:*:*:*", "vulnerable": true, "matchCriteriaId": "7E6936EB-0F07-4A88-866E-A93B36603C0D" }, { "criteria": "cpe:2.3:a:oneidentity:syslog-ng:3.2:*:*:*:premium:*:*:*", "vulnerable": true, "matchCriteriaId": "C19115A4-CDE5-4D3C-A090-050028EEB6BB" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D9EC02F3-3905-460D-8949-3B26394215CA" }, { "criteria": "cpe:2.3:o:hp:hp-ux:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "61A4F116-1FEE-450E-99AE-6AD9ACDDE570" } ], "operator": "OR" } ], "operator": "AND" } ]