CVE-2022-1348
Dashboard / Vulnerabilities / CVE-2022-1348
CVE-2022-1348
Summary:
Details: A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation. This flaw affects logrotate versions before 3.20.0.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1348.json, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y7EHGYRE6DSFSBXQIWYDGTSXKO6IFSJQ/, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZYEB4F37BY6GLEJKP2EPVAVQ6TA3HQKR/, https://nvd.nist.gov/vuln/detail/CVE-2022-1348, https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2022-1348, http://www.openwall.com/lists/oss-security/2022/05/25/3, http://www.openwall.com/lists/oss-security/2022/05/25/4, http://www.openwall.com/lists/oss-security/2022/05/25/5
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
