CVE Vulnerabilities

CVE-2011-0343

Published: Jan 28, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes syslog-ng to use a default value of -1 to create log files with insecure permissions (07777), which allows local users to read and write to these log files.

Affected Software

NameVendorStart VersionEnd Version
Syslog-ngOneidentity2.0 (including)2.0 (including)
Syslog-ngOneidentity3.0 (including)3.0 (including)
Syslog-ngOneidentity3.1 (including)3.1 (including)
Syslog-ngOneidentity3.2 (including)3.2 (including)
Syslog-ngUbuntuartful*
Syslog-ngUbuntudapper*
Syslog-ngUbuntuhardy*
Syslog-ngUbuntukarmic*
Syslog-ngUbuntulucid*
Syslog-ngUbuntumaverick*
Syslog-ngUbuntunatty*
Syslog-ngUbuntuoneiric*
Syslog-ngUbuntuprecise*
Syslog-ngUbuntuquantal*
Syslog-ngUbunturaring*
Syslog-ngUbuntusaucy*
Syslog-ngUbuntuupstream*
Syslog-ngUbuntuutopic*
Syslog-ngUbuntuvivid*
Syslog-ngUbuntuwily*
Syslog-ngUbuntuyakkety*
Syslog-ngUbuntuzesty*

References