A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation. This flaw affects logrotate versions before 3.20.0.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published: 2022-05-25T15:13:39
Updated: 2024-08-03T00:03:05.887Z
Reserved: 2022-04-13T00:00:00
Link: CVE-2022-1348

No data.

Status : Modified
Published: 2022-05-25T16:15:08.150
Modified: 2024-11-21T06:40:32.640
Link: CVE-2022-1348
