Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes syslog-ng to use a default value of -1 to create log files with insecure permissions (07777), which allows local users to read and write to these log files.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Balabit syslog-ng日志文件权限安全问题漏洞
Vulnerability Description
BalaBit IT Security syslog-ng是一款系统日志记录工具, 可用于替代标准的Unix系统日志记录程序syslogd。 基于FreeBSD或HP-UX平台的Balabit syslog-ng 2.0,3.0,3.1,3.2 OSE及PE版本没有正确执行转换操作,此操作可以导致syslog-ng使用-1默认值创建带有不安全许可(07777)的日志文件。本地用户可以利用该漏洞对这些日志文件进行读写。
CVSS Information
N/A
Vulnerability Type
N/A