Required CVE Record Information
Description
The setup_logging function in log.h in SANLock uses world-writable permissions for /var/log/sanlock.log, which allows local users to overwrite the file content or bypass intended disk-quota restrictions via standard filesystem write operations.
References 2 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 2 Total
- rhn.redhat.com: RHSA-2013:0691 vendor-advisoryx_transferred
- https://bugzilla.redhat.com/show_bug.cgi?id=887010 x_transferred