PT-2011-3210 · Suse · Logrotate

Ludwig Nussel

·

Published

2011-03-30

·

Updated

2011-04-07

·

CVE-2011-1550

CVSS v2.0

6.3

Medium

VectorAV:L/AC:M/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions logrotate on SUSE openSUSE Factory
Description The issue arises from the default configuration of logrotate, which uses root privileges to process files in directories that allow non-root write access. This lack of support for untrusted directories enables local users to perform symlink and hard link attacks. The vulnerability can be demonstrated in directories for various packages, including cobbler, inn, safte-monitor, and uucp.
Recommendations For logrotate on SUSE openSUSE Factory, consider reconfiguring logrotate to avoid processing files in directories with non-root write access as a temporary workaround. Restrict access to these directories to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1550

Affected Products

Logrotate