|
|
| |
|
| |
logrotate: symlink and hard link attacks
| Package(s): | logrotate |
CVE #(s): | CVE-2011-1549
|
| Created: | June 26, 2012 |
Updated: | June 27, 2012 |
| Description: |
From the CVE entry:
The default configuration of logrotate on Gentoo Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by directories under /var/log/ for packages. |
| Alerts: |
|
( Log in to post comments)
|
|
|