SUSE-SU-2022:2396-1
Dashboard / Vulnerabilities / SUSE-SU-2022:2396-1
SUSE-SU-2022:2396-1
Summary: Security update for logrotate
Details: This update for logrotate fixes the following issues: Security issues fixed: - CVE-2022-1348: Fixed insecure permissions for state file creation (bsc#1199652). - Improved coredump handing for SUID binaries (bsc#1192449). Non-security issues fixed: - Fixed 'logrotate emits unintended warning: keyword size not properly separated, found 0x3d' (bsc#1200278, bsc#1200802).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20222396-1/, https://bugzilla.suse.com/1192449, https://bugzilla.suse.com/1199652, https://bugzilla.suse.com/1200278, https://bugzilla.suse.com/1200802, https://www.suse.com/security/cve/CVE-2022-1348
Affected packages
Package
Name: logrotate
Purl: pkg:rpm/suse/logrotate&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
