rsyslog: some log files are created world-readable
Published Jul 25, 2017
5.5
MEDIUMCVSS 3.0
EPSS 0.45%
Description
rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by reading files in /var/log/cron.
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
rsyslog
Not affected
Red Hat Enterprise Linux 6
rsyslog
Not affected
Red Hat Enterprise Linux 7
rsyslog
Affected
Red Hat Storage 2
rsyslog
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | rsyslog | Not affected | n/a |
| Red Hat Enterprise Linux 6 | rsyslog | Not affected | n/a |
| Red Hat Enterprise Linux 7 | rsyslog | Affected | n/a |
| Red Hat Storage 2 | rsyslog | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of rsyslog as shipped with Red Hat Enterprise Linux 7. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/. Additionally a workaround is available (https://bugzilla.redhat.com/show_bug.cgi?id=1232826#c3).
Red Hat mitigation
Please add: create 0600 root root to the /etc/logrotate.d/syslog file, this will ensure the file is created with permissions when logrotate runs. It is also recommended that users manually set the permissions on existing or newly installed log files in order to prevent access by untrusted users.
References (8)
- http://www.openwall.com/lists/oss-security/2015/06/18/12 mailing-listx_refsource_MLISTMailing ListVDB Entry
- http://www.openwall.com/lists/oss-security/2015/06/20/3 mailing-listx_refsource_MLISTMailing ListVDB Entry
- http://www.securityfocus.com/bid/75298 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1032885 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2015-3243 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1232826 x_refsource_CONFIRMIssue TrackingThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2015-3243
- https://www.cve.org/CVERecord?id=CVE-2015-3243
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2015/06/18/12 | mailing-listx_refsource_MLISTMailing ListVDB Entry | |
| http://www.openwall.com/lists/oss-security/2015/06/20/3 | mailing-listx_refsource_MLISTMailing ListVDB Entry | |
| http://www.securityfocus.com/bid/75298 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id/1032885 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2015-3243 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1232826 | x_refsource_CONFIRMIssue TrackingThird Party AdvisoryVDB Entry | |
| https://nvd.nist.gov/vuln/detail/CVE-2015-3243 | ||
| https://www.cve.org/CVERecord?id=CVE-2015-3243 |
Change history (0)
No recorded changes yet.