Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes syslog-ng to use a default value of -1 to create log files with insecure permissions (07777), which allows local users to read and write to these log files.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=608491 | third party advisory patch |
http://www.securityfocus.com/archive/1/515955/100/0/threaded | mailing list vdb entry third party advisory |
https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000101.html | mailing list vendor advisory |
https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000102.html | mailing list vendor advisory |
http://www.securityfocus.com/bid/45988 | vdb entry third party advisory |