OESA-2022-1724
Dashboard / Vulnerabilities / OESA-2022-1724
Summary: logrotate security update
Details: The logrotate utility is designed to simplify the administration of log files on a system which generates a lot of log files. Logrotate allows for the automatic rotation compression, removal and mailing of log files.logrotate Logrotate can be set to handle a log file daily, weekly, monthly or when the log file gets to a certain size. Security Fix(es): A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation. This flaw affects logrotate versions before 3.20.0.(CVE-2022-1348)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1724, https://nvd.nist.gov/vuln/detail/CVE-2022-1348
Affected packages
Package
Name: logrotate
Purl: pkg:rpm/openEuler/logrotate&distro=openEuler-22.03-LTS
Affected ranges
Type: ECOSYSTEM
Events:
