CVE-2011-0343
Publication date 28 January 2011
Last updated 24 July 2024
Ubuntu priority
Description
Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes syslog-ng to use a default value of -1 to create log files with insecure permissions (07777), which allows local users to read and write to these log files.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| syslog-ng | 18.04 LTS bionic |
Not affected
|
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Not affected
|
|
Notes
sbeattie
only affects people running syslog-ng on kfreebsd, as fchmod when passed with -1 doesn't change the mode on files.
Patch details
| Package | Patch details |
|---|---|
| syslog-ng |