~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
Candidate: CVE-2011-1550
PublicDate: 2011-03-30
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1550
 http://openwall.com/lists/oss-security/2011/03/04/16
Description:
 The default configuration of logrotate on SUSE openSUSE Factory uses root
 privileges to process files in directories that permit non-root write
 access, which allows local users to conduct symlink and hard link attacks
 by leveraging logrotate's lack of support for untrusted directories, as
 demonstrated by directories for the (1) cobbler, (2) inn, (3)
 safte-monitor, and (4) uucp packages.
Ubuntu-Description:
Notes:
 mdeslaur> SUSE-specific CVE (see CVE-2011-1548 for Debian)
Bugs:
Priority: medium
Discovered-by:
Assigned-to:

Patches_logrotate:
upstream_logrotate: needs-triage
dapper_logrotate: not-affected
hardy_logrotate: not-affected
karmic_logrotate: not-affected
lucid_logrotate: not-affected
maverick_logrotate: not-affected
devel_logrotate: not-affected