A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation. This flaw affects logrotate versions before 3.20.0.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2022-05-25T15:13:39
Updated: 2024-08-03T00:03:05.887Z
Reserved: 2022-04-13T00:00:00
Link: CVE-2022-1348
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-05-25T16:15:08.150
Modified: 2024-11-21T06:40:32.640
Link: CVE-2022-1348
Redhat