Vulnerability CVE-2022-1348: Information

Description

A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation. This flaw affects logrotate versions before 3.20.0.

Severity: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Published: May 25, 2022
Modified: Nov. 7, 2023
Error type identifier: CWE-732

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
logrotatesisyphus3.20.1-alt13.20.1-alt2ALT-PU-2022-1955-1300834Fixed
logrotatesisyphus_e2k3.20.1-alt13.20.1-alt2ALT-PU-2022-5450-1-Fixed
logrotatesisyphus_riscv643.20.1-alt13.20.1-alt2ALT-PU-2022-5090-1-Fixed
logrotatep103.20.1-alt23.20.1-alt2ALT-PU-2023-1925-1321948Fixed
logrotatep10_e2k3.20.1-alt23.20.1-alt2ALT-PU-2023-3802-1-Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:logrotate_project:logrotate:*:*:*:*:*:*:*:*
      Start including
      3.17.0
      End excliding
      3.20.0

      Configuration 2

      cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*