CVE-2011-1549 - CERT CVE
ID CVE-2011-1549
Sažetak The default configuration of logrotate on Gentoo Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by directories under /var/log/ for packages.
Reference
CVSS
Base: 6.3
Impact: 9.2
Exploitability:3.4
Pristup
VektorSloženostAutentikacija
LOCAL MEDIUM NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE COMPLETE COMPLETE
CVSS vektor AV:L/AC:M/Au:N/C:N/I:C/A:C
Zadnje važnije ažuriranje 21-04-2011 - 02:33
Objavljeno 30-03-2011 - 22:55