|
|
| |
|
| |
logrotate: symlink and hard link attacks
| Package(s): | logrotate |
CVE #(s): | CVE-2011-1548
|
| Created: | July 21, 2011 |
Updated: | July 27, 2011 |
| Description: |
From the CVE entry:
The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by /var/log/postgresql/. |
| Alerts: |
|
( Log in to post comments)
|
|
|