Oval Definition:oval:com.ubuntu.trusty:def:20110343000
Revision Date:2011-01-28Version:1
Title:CVE-2011-0343 on Ubuntu 14.04 LTS (trusty) - low.
Description:Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes syslog-ng to use a default value of -1 to create log files with insecure permissions (07777), which allows local users to read and write to these log files.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2011-0343
Platform(s):Ubuntu 14.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 14.04 LTS (trusty) is installed.
  • AND NOT While related to the CVE in some way, the 'syslog-ng' package in trusty is not affected (note: '3.1.3-2').
  • BACK