Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by /var/log/postgresql/.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Gentoo logrotate默认配置后置链接漏洞
Vulnerability Description
logrotate是一款系统日志管理软件。 基于Debian GNU/Linux的logrotate默认配置使用根权限去处理目录中的文件(允许低权限用户对该文件执行写操作)。本地用户可以利用logrotate支持不可信路径的缺陷,执行符号链接和硬链接攻击。该漏洞已经通过/var/log/postgresql/得到证实。
CVSS Information
N/A
Vulnerability Type
N/A