A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation. This flaw affects logrotate versions before 3.20.0.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade logrotate | Nov 18, 2022 | May 25, 2022 |
| Alpine Linux | — | Upgrade logrotate | Mar 26, 2024 | May 25, 2022 |
| Centos_linux | — | Upgrade logrotate-debuginfoUpgrade logrotateUpgrade logrotate-debugsource | Nov 16, 2022 | May 25, 2022 |
| Debian | — | Upgrade logrotate | Jul 30, 2024 | May 25, 2022 |
| Oracle_linux | — | Upgrade logrotate | Nov 22, 2022 | May 25, 2022 |
| Redhat_linux | — | Upgrade logrotate-debugsourceUpgrade logrotate-debuginfoUpgrade logrotate | Nov 16, 2022 | May 25, 2022 |
| Rocky_linux | — | Upgrade logrotate-debugsourceUpgrade logrotateUpgrade logrotate-debuginfo | Mar 12, 2024 | May 25, 2022 |
| Suse | — | Upgrade logrotate | Oct 26, 2022 | May 25, 2022 |
| Ubuntu | — | Upgrade logrotate | May 27, 2022 | May 25, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | May 25, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub