oss-sec mailing list archives

CVE request: Icecast world readable log/logdir


From: Agostino Sarubbo <ago () gentoo org>
Date: Sun, 06 Apr 2014 19:32:41 +0200

I just noticed that (at least on gentoo), the following package produces a 
world readable log:

Icecast (http://www.icecast.org):
# ls -la /var/log/icecast 
total 18648
drwxrw-r--  2 icecast nogroup     4096 Apr  6 12:23 .
drwxr-xr-x 15 root    root        4096 Apr  5 04:20 ..
-rw-r--r--  1 icecast nogroup  5646894 Apr  6 19:27 access.log
-rw-r--r--  1 icecast nogroup  3181987 Apr  6 19:27 error.log
-- 
Agostino Sarubbo
Gentoo Linux Developer


Current thread: