UBUNTU-CVE-2022-1348
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-1348
UBUNTU-CVE-2022-1348
Summary:
Details: A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation. This flaw affects logrotate versions before 3.20.0.
References: https://ubuntu.com/security/CVE-2022-1348, https://github.com/logrotate/logrotate/blame/master/logrotate.c#L3015-L3017, https://github.com/logrotate/logrotate/commit/f46d0bdfc9c53515c13880c501f4d2e1e7dd8b25, https://ubuntu.com/security/notices/USN-5447-1, https://www.cve.org/CVERecord?id=CVE-2022-1348
Affected packages
Package
Name: logrotate
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=jammy
Affected ranges
Type: ECOSYSTEM
Events:
