Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-1098

Опубликовано: 13 фев. 2011
Источник: redhat
CVSS2: 1.9

Описание

Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the intended permissions are in place.

Отчет

The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4logrotateWill not fix
Red Hat Enterprise Linux 5logrotateWill not fix
Red Hat Enterprise Linux 6logrotateFixedRHSA-2011:040731.03.2011

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=680798logrotate: TOCTOU race condition by creation of new files (between opening the file and moment, final permissions have been applied) [information disclosure]

1.9 Low

CVSS2

Связанные уязвимости

ubuntu
около 14 лет назад

Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the intended permissions are in place.

nvd
около 14 лет назад

Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the intended permissions are in place.

debian
около 14 лет назад

Race condition in the createOutputFile function in logrotate.c in logr ...

github
около 3 лет назад

Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the intended permissions are in place.

oracle-oval
около 14 лет назад

ELSA-2011-0407: logrotate security update (MODERATE)

1.9 Low

CVSS2