MGASA-2022-0217

Source
https://advisories.mageia.org/MGASA-2022-0217.html
Import Source
https://advisories.mageia.org/MGASA-2022-0217.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2022-0217
Related
Published
2022-06-03T17:15:11Z
Modified
2022-06-03T16:24:58Z
Summary
Updated logrotate packages fix security vulnerability
Details

A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation. This flaw affects logrotate versions before 3.20.0. (CVE-2022-1348) Note the change in permission does not apply until the first time logrotate runs after installing the update.

References
Credits

Affected packages

Mageia:8 / logrotate

Package

Name
logrotate
Purl
pkg:rpm/mageia/logrotate?arch=source&distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.17.0-3.1.mga8

Ecosystem specific

{
    "section": "core"
}