Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-1348

Опубликовано: 25 мая 2022
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation. This flaw affects logrotate versions before 3.20.0.

A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-mover-rclone-rhel8Not affected
Red Hat Enterprise Linux 6logrotateNot affected
Red Hat Enterprise Linux 7logrotateNot affected
Red Hat Enterprise Linux 8logrotateNot affected
Red Hat Enterprise Linux 9logrotateFixedRHSA-2022:839315.11.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=2075074logrotate: potential DoS from unprivileged users via the state file

EPSS

Процентиль: 27%
0.00092
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 3 лет назад

A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation. This flaw affects logrotate versions before 3.20.0.

CVSS3: 6.5
nvd
около 3 лет назад

A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation. This flaw affects logrotate versions before 3.20.0.

CVSS3: 6.5
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 6.5
debian
около 3 лет назад

A vulnerability was found in logrotate in how the state file is create ...

suse-cvrf
около 3 лет назад

Security update for logrotate

EPSS

Процентиль: 27%
0.00092
Низкий

6.2 Medium

CVSS3