Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Steven Chamberlain

#41856of 56,330
6.9Total CVSS
Vulnerabilities · 1
PT-2011-2282
6.9
2011-01-28
Balabit · Syslog-Ng · CVE-2011-0343
**Name of the Vulnerable Software and Affected Versions** Balabit syslog-ng versions 2.0, 3.0, 3.1, 3.2 OSE and PE **Description** The issue is related to improper cast operations when running on certain operating systems, resulting in the creation of log files with insecure permissions. This allows local users to read and write to these log files. **Recommendations** For Balabit syslog-ng versions 2.0, 3.0, 3.1, 3.2 OSE and PE, consider changing the default permissions to a more secure setting to prevent unauthorized access to log files.