Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The setup_logging function in log.h in SANLock uses world-writable permissions for /var/log/sanlock.log, which allows local users to overwrite the file content or bypass intended disk-quota restrictions via standard filesystem write operations.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SANLock 日志文件不安全权限漏洞
Vulnerability Description
sanlock后台程序用于管理运行在共享存储集群主机上的应用程序。 SANLock中的log.h中的‘setup_logging’函数中存在漏洞,该漏洞源于/var/log/sanlock.log使用全局可写权限。通过标准的文件系统写入操作,本地攻击者利用该漏洞重写任意文件内容或绕过预期的disk-quota限制。
CVSS Information
N/A
Vulnerability Type
N/A