SANLock 'sanlock.log' File Insecure File Permissions Vulnerability
BID:56971
Info
SANLock 'sanlock.log' File Insecure File Permissions Vulnerability
| Bugtraq ID: | 56971 |
| Class: | Design Error |
| CVE: |
CVE-2012-5638 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 13 2012 12:00AM |
| Updated: | Dec 13 2012 12:00AM |
| Credit: | Kurt Seifried |
| Vulnerable: |
SANLock SANLock 2.4 |
| Not Vulnerable: | |
Discussion
SANLock 'sanlock.log' File Insecure File Permissions Vulnerability
SANLock is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue to obtain potentially sensitive information and modify or delete logs. Information obtained may aid in further attacks.
SANLock 2.4 is vulnerable; other versions may also be affected.
SANLock is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue to obtain potentially sensitive information and modify or delete logs. Information obtained may aid in further attacks.
SANLock 2.4 is vulnerable; other versions may also be affected.
Exploit / POC
SANLock 'sanlock.log' File Insecure File Permissions Vulnerability
Attackers can use readily available tools and standard commands to exploit this issue.
Attackers can use readily available tools and standard commands to exploit this issue.
Solution / Fix
SANLock 'sanlock.log' File Insecure File Permissions Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
SANLock 'sanlock.log' File Insecure File Permissions Vulnerability
References:
References:
- Bug 887010 - (CVE-2012-5638) CVE-2012-5638 sanlock world writable /var/log/sanlo (Red Hat Bugzilla)
- SANLock Homepage (Fedora)