Files
meta-openembedded/meta-oe/recipes-extended
Gyorgy Sarvari 38ea8a4617 rsyslog: set status for CVE-2015-3243
Details: https://nvd.nist.gov/vuln/detail/CVE-2015-3243

The issue is about file permissions: by default rsyslog creates world-readable
files. In case a log message contains some sensitive information, then that's
exposed to every user on the system.

However the rsyslog.conf file that is shipped with the recipe solves it: it
already sets non-world-readable default permissions on all files, so this
vulnerability is fixed in the default OE recipe.

See also this package in OpenSuse[1], where it is solved the same way.

[1]: https://build.opensuse.org/requests/619439/changes (rsyslog.conf.in)

Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
2025-11-14 07:39:48 -08:00
..
2025-08-29 15:36:56 -07:00
2025-01-07 09:33:14 -08:00
2025-09-27 16:18:15 -07:00
2025-03-25 09:33:50 -07:00
2025-04-08 08:22:05 -07:00
2025-09-06 10:11:38 -07:00
2025-10-06 14:14:36 -07:00
2025-08-20 07:35:08 -07:00
2025-09-04 10:28:23 -07:00
2025-08-20 07:35:08 -07:00
2025-09-27 16:18:15 -07:00
2025-07-30 08:03:06 -07:00
2025-03-31 14:42:06 -07:00
2025-11-06 16:00:50 -08:00
2025-06-09 21:24:11 -07:00
2024-08-09 14:25:15 -07:00
2024-12-03 09:44:33 -08:00
2025-07-30 16:40:03 -07:00
2025-07-25 17:12:12 -07:00
2025-11-13 10:15:06 -08:00
2024-09-11 21:15:34 -07:00
2025-10-14 09:00:25 -07:00
2025-08-09 10:22:39 -07:00
2024-09-30 07:34:28 -07:00
2025-07-11 08:35:05 -07:00
2025-10-08 18:46:03 -07:00
2025-09-24 10:54:44 -07:00