Vulnerability CVE-2011-1098: Information

Description

Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the intended permissions are in place.

Severity: LOW (1.9)

Published: March 31, 2011
Modified: Feb. 13, 2023
Error type identifier: CWE-362

References to Advisories, Solutions, and Tools

Hyperlink
Resource
[oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
    [oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
      [oss-security] 20110305 Re: CVE Request -- logrotate -- nine issues
        [oss-security] 20110323 Re: CVE Request -- logrotate -- nine issues
          [oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
            https://bugzilla.redhat.com/show_bug.cgi?id=680798
            • Patch
            [oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
              [oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
                [oss-security] 20110306 Re: CVE Request -- logrotate -- nine issues
                  [oss-security] 20110304 CVE Request -- logrotate -- nine issues
                  • Patch
                  [oss-security] 20110306 Re: CVE Request -- logrotate -- nine issues
                    [oss-security] 20110308 Re: CVE Request -- logrotate -- nine issues
                      [oss-security] 20110311 Re: CVE Request -- logrotate -- nine issues
                        [oss-security] 20110311 Re: CVE Request -- logrotate -- nine issues
                          [oss-security] 20110311 Re: CVE Request -- logrotate -- nine issues
                            [oss-security] 20110306 Re: CVE Request -- logrotate -- nine issues
                              [oss-security] 20110307 Re: CVE Request -- logrotate -- nine issues
                                ADV-2011-0791
                                • Vendor Advisory
                                [oss-security] 20110307 Re: CVE Request -- logrotate -- nine issues
                                • Patch
                                [oss-security] 20110306 Re: CVE Request -- logrotate -- nine issues
                                  [oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
                                    [oss-security] 20110305 Re: CVE Request -- logrotate -- nine issues
                                      FEDORA-2011-3758
                                      • Patch
                                      [oss-security] 20110306 Re: CVE Request -- logrotate -- nine issues
                                        [oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
                                          [oss-security] 20110310 Re: CVE Request -- logrotate -- nine issues
                                            [oss-security] 20110307 Re: CVE Request -- logrotate -- nine issues
                                              [oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
                                                [oss-security] 20110310 Re: CVE Request -- logrotate -- nine issues
                                                  [oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
                                                    [oss-security] 20110314 Re: CVE Request -- logrotate -- nine issues
                                                      [oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
                                                        [oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
                                                          [oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
                                                            [oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
                                                              [oss-security] 20110311 Re: CVE Request -- logrotate -- nine issues
                                                                [oss-security] 20110305 Re: CVE Request -- logrotate -- nine issues
                                                                  43955
                                                                    ADV-2011-0961
                                                                      RHSA-2011:0407
                                                                        ADV-2011-0872
                                                                          FEDORA-2011-3739
                                                                            MDVSA-2011:065
                                                                                1. Configuration 1

                                                                                  cpe:2.3:a:gentoo:logrotate:3.6.5:*:*:*:*:*:*:*

                                                                                  cpe:2.3:a:gentoo:logrotate:3.7.8:*:*:*:*:*:*:*

                                                                                  cpe:2.3:a:gentoo:logrotate:3.5.9:r1:*:*:*:*:*:*

                                                                                  cpe:2.3:a:gentoo:logrotate:3.7.6:*:*:*:*:*:*:*

                                                                                  cpe:2.3:a:gentoo:logrotate:3.3:r2:*:*:*:*:*:*

                                                                                  cpe:2.3:a:gentoo:logrotate:3.7.2:*:*:*:*:*:*:*

                                                                                  cpe:2.3:a:gentoo:logrotate:3.7:*:*:*:*:*:*:*

                                                                                  cpe:2.3:a:gentoo:logrotate:3.7.1:r2:*:*:*:*:*:*

                                                                                  cpe:2.3:a:gentoo:logrotate:3.6.5:r1:*:*:*:*:*:*

                                                                                  cpe:2.3:a:gentoo:logrotate:3.5.9:*:*:*:*:*:*:*

                                                                                  cpe:2.3:a:gentoo:logrotate:3.7.1:r1:*:*:*:*:*:*

                                                                                  cpe:2.3:a:gentoo:logrotate:*:*:*:*:*:*:*:*
                                                                                  End including
                                                                                  3.7.9

                                                                                  cpe:2.3:a:gentoo:logrotate:3.7.1:*:*:*:*:*:*:*

                                                                                  cpe:2.3:a:gentoo:logrotate:3.7.7:*:*:*:*:*:*:*