Candidate: CVE-2011-0343 PublicDate: 2011-01-28 16:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0343 Description: Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes syslog-ng to use a default value of -1 to create log files with insecure permissions (07777), which allows local users to read and write to these log files. Ubuntu-Description: Notes: sbeattie> only affects people running syslog-ng on kfreebsd, as fchmod when passed with -1 doesn't change the mode on files. Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_syslog-ng: upstream: http://git.balabit.hu/?p=bazsi/syslog-ng-3.1.git;a=commitdiff;h=cbcea8c95c3f07ed9eaa4d12f124db8f8ca2f74b;hp=61181dca938d2cdd8233df2a07d6e0c76f049e6f upstream_syslog-ng: released (3.0.10, 3.1.4) dapper_syslog-ng: ignored (reached end-of-life) hardy_syslog-ng: ignored (reached end-of-life) karmic_syslog-ng: ignored (reached end-of-life) lucid_syslog-ng: ignored (reached end-of-life) maverick_syslog-ng: ignored (reached end-of-life) natty_syslog-ng: ignored (reached end-of-life) oneiric_syslog-ng: ignored (reached end-of-life) precise_syslog-ng: ignored (reached end-of-life) precise/esm_syslog-ng: DNE (precise was needed) quantal_syslog-ng: ignored (reached end-of-life) raring_syslog-ng: ignored (reached end-of-life) saucy_syslog-ng: ignored (reached end-of-life) trusty_syslog-ng: not-affected (3.1.3-2) trusty/esm_syslog-ng: not-affected (3.1.3-2) utopic_syslog-ng: ignored (reached end-of-life) vivid_syslog-ng: ignored (reached end-of-life) vivid/stable-phone-overlay_syslog-ng: DNE vivid/ubuntu-core_syslog-ng: DNE wily_syslog-ng: ignored (reached end-of-life) xenial_syslog-ng: not-affected (3.1.3-2) yakkety_syslog-ng: ignored (reached end-of-life) zesty_syslog-ng: ignored (reached end-of-life) artful_syslog-ng: ignored (reached end-of-life) bionic_syslog-ng: not-affected (3.1.3-2) devel_syslog-ng: not-affected (3.1.3-2)