The setup_logging function in log.h in SANLock uses world-writable permissions for /var/log/sanlock.log, which allows local users to overwrite the file content or bypass intended disk-quota restrictions via standard filesystem write operations.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sanlock | Ovirt | - (including) | - (including) |