CVE-2011-1098
published 2011-03-30CVE-2011-1098: Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the…
PriorityP45low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.28%
20.4th percentile
Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the intended permissions are in place.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | logrotate | < logrotate 3.8.0-1 (bookworm) | logrotate 3.8.0-1 (bookworm) |
| gentoo | logrotate | <= 3.7.9 | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| logrotate_project | logrotate | >= 0 < 3.8.0-1 | 3.8.0-1 |
| logrotate_project | logrotate | >= 0 < 3.8.0-1 | 3.8.0-1 |
| logrotate_project | logrotate | >= 0 < 3.8.0-1 | 3.8.0-1 |
| logrotate_project | logrotate | >= 0 < 3.8.0-1 | 3.8.0-1 |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv1.9LOW
vendor_debian1.9LOW
vendor_redhat1.9LOW
vendor_ubuntu1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
logrotate vulnerabilities
vendor_ubuntu·2011-07-21·CVSS 1.9
CVE-2011-1098 [LOW] logrotate vulnerabilities
Title: logrotate vulnerabilities
Summary: An attacker could cause logrotate to run programs, stop working, or read
and write arbitrary files.
It was discovered that logrotate incorrectly handled the creation of new
log files. Local users could possibly read log files if they were opened
before permissions were in place. This issue only affected Ubuntu 8.04 LTS.
(CVE-2011-1098)
It was discovered that logrotate incorrectly handled certain log file
names when used with the shred option. Local attackers able to create log
files with specially crafted filenames could use this issue to execute
arbitrary code. This issue only affected Ubuntu 10.04 LTS, 10.10, and
11.04. (CVE-2011-1154)
It was discovered that logrotate incorrectly handled certain malformed log
filenames. Local attackers able t
Red Hat
logrotate: TOCTOU race condition by creation of new files (between opening the file and moment, final permissions have been applied) [information disclosure]
vendor_redhat·2011-02-13·CVSS 1.9
CVE-2011-1098 [LOW] CWE-367 logrotate: TOCTOU race condition by creation of new files (between opening the file and moment, final permissions have been applied) [information disclosure]
logrotate: TOCTOU race condition by creation of new files (between opening the file and moment, final permissions have been applied) [information disclosure]
Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the intended permissions are in place.
Statement: The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.
Package: logrotate (Red Hat Enterprise Linux 4) - Will not fix
Package: logrotate (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2011-1098: logrotate - Race condition in the createOutputFile function in logrotate.c in logrotate 3.7....
vendor_debian·2011·CVSS 1.9
CVE-2011-1098 [LOW] CVE-2011-1098: logrotate - Race condition in the createOutputFile function in logrotate.c in logrotate 3.7....
Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the intended permissions are in place.
Scope: local
bookworm: resolved (fixed in 3.8.0-1)
bullseye: resolved (fixed in 3.8.0-1)
forky: resolved (fixed in 3.8.0-1)
sid: resolved (fixed in 3.8.0-1)
trixie: resolved (fixed in 3.8.0-1)
GHSA
GHSA-h8gr-59qr-mxm6: Race condition in the createOutputFile function in logrotate
ghsa_unreviewed·2022-05-17
CVE-2011-1098 [LOW] CWE-362 GHSA-h8gr-59qr-mxm6: Race condition in the createOutputFile function in logrotate
Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the intended permissions are in place.
OSV
CVE-2011-1098: Race condition in the createOutputFile function in logrotate
osv·2011-03-30·CVSS 1.9
CVE-2011-1098 [LOW] CVE-2011-1098: Race condition in the createOutputFile function in logrotate
Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the intended permissions are in place.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1098 CVE-2011-1154 CVE-2011-1155 logrotate various flaws [fedora-all]
bugzilla·2011-03-17·CVSS 1.9
CVE-2011-1098 [LOW] CVE-2011-1098 CVE-2011-1154 CVE-2011-1155 logrotate various flaws [fedora-all]
CVE-2011-1098 CVE-2011-1154 CVE-2011-1155 logrotate various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=680798
Please note: this issue affects mult
Bugzilla
CVE-2011-1098 logrotate: TOCTOU race condition by creation of new files (between opening the file and moment, final permissions have been applied) [information disclosure]
bugzilla·2011-02-27·CVSS 1.9
CVE-2011-1098 [LOW] CVE-2011-1098 logrotate: TOCTOU race condition by creation of new files (between opening the file and moment, final permissions have been applied) [information disclosure]
CVE-2011-1098 logrotate: TOCTOU race condition by creation of new files (between opening the file and moment, final permissions have been applied) [information disclosure]
It was found that logrotate utility used insecure default
permissions, when creating of new files (time-of-check,
time-of-use, TOCTOU race condition). In some specific
configurations, a local attacker could use this flaw to
open the new file before the final permissions have been
applied, leading to disclosure of sensitive information.
Discussion:
Further flaw details from Stefan Fritsch of Debian Security Team:
The race is between
192 fd = open(fileName, flags, sb->st_mode);
and
198 if (fchmod(fd, (S_IRUSR | S_IWUSR) & sb->st_mode)) {
and later
204 if (fchown(fd, sb->st_uid, sb->st_gid)) {
An attacker may be
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057845.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056992.htmlhttp://openwall.com/lists/oss-security/2011/03/04/16http://openwall.com/lists/oss-security/2011/03/04/17http://openwall.com/lists/oss-security/2011/03/04/18http://openwall.com/lists/oss-security/2011/03/04/19http://openwall.com/lists/oss-security/2011/03/04/22http://openwall.com/lists/oss-security/2011/03/04/24http://openwall.com/lists/oss-security/2011/03/04/25http://openwall.com/lists/oss-security/2011/03/04/26http://openwall.com/lists/oss-security/2011/03/04/27http://openwall.com/lists/oss-security/2011/03/04/28http://openwall.com/lists/oss-security/2011/03/04/29http://openwall.com/lists/oss-security/2011/03/04/30http://openwall.com/lists/oss-security/2011/03/04/31http://openwall.com/lists/oss-security/2011/03/04/32http://openwall.com/lists/oss-security/2011/03/04/33http://openwall.com/lists/oss-security/2011/03/05/4http://openwall.com/lists/oss-security/2011/03/05/6http://openwall.com/lists/oss-security/2011/03/05/8http://openwall.com/lists/oss-security/2011/03/06/3http://openwall.com/lists/oss-security/2011/03/06/4http://openwall.com/lists/oss-security/2011/03/06/5http://openwall.com/lists/oss-security/2011/03/06/6http://openwall.com/lists/oss-security/2011/03/07/11http://openwall.com/lists/oss-security/2011/03/07/5http://openwall.com/lists/oss-security/2011/03/07/6http://openwall.com/lists/oss-security/2011/03/08/5http://openwall.com/lists/oss-security/2011/03/10/2http://openwall.com/lists/oss-security/2011/03/10/3http://openwall.com/lists/oss-security/2011/03/10/6http://openwall.com/lists/oss-security/2011/03/10/7http://openwall.com/lists/oss-security/2011/03/11/3http://openwall.com/lists/oss-security/2011/03/11/5http://openwall.com/lists/oss-security/2011/03/14/26http://openwall.com/lists/oss-security/2011/03/23/11http://secunia.com/advisories/43955http://www.mandriva.com/security/advisories?name=MDVSA-2011:065http://www.redhat.com/support/errata/RHSA-2011-0407.htmlhttp://www.vupen.com/english/advisories/2011/0791http://www.vupen.com/english/advisories/2011/0872http://www.vupen.com/english/advisories/2011/0961https://bugzilla.redhat.com/show_bug.cgi?id=680798http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057845.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056992.htmlhttp://openwall.com/lists/oss-security/2011/03/04/16http://openwall.com/lists/oss-security/2011/03/04/17http://openwall.com/lists/oss-security/2011/03/04/18http://openwall.com/lists/oss-security/2011/03/04/19http://openwall.com/lists/oss-security/2011/03/04/22http://openwall.com/lists/oss-security/2011/03/04/24http://openwall.com/lists/oss-security/2011/03/04/25http://openwall.com/lists/oss-security/2011/03/04/26http://openwall.com/lists/oss-security/2011/03/04/27http://openwall.com/lists/oss-security/2011/03/04/28http://openwall.com/lists/oss-security/2011/03/04/29http://openwall.com/lists/oss-security/2011/03/04/30http://openwall.com/lists/oss-security/2011/03/04/31http://openwall.com/lists/oss-security/2011/03/04/32http://openwall.com/lists/oss-security/2011/03/04/33http://openwall.com/lists/oss-security/2011/03/05/4http://openwall.com/lists/oss-security/2011/03/05/6http://openwall.com/lists/oss-security/2011/03/05/8http://openwall.com/lists/oss-security/2011/03/06/3http://openwall.com/lists/oss-security/2011/03/06/4http://openwall.com/lists/oss-security/2011/03/06/5http://openwall.com/lists/oss-security/2011/03/06/6http://openwall.com/lists/oss-security/2011/03/07/11http://openwall.com/lists/oss-security/2011/03/07/5http://openwall.com/lists/oss-security/2011/03/07/6http://openwall.com/lists/oss-security/2011/03/08/5http://openwall.com/lists/oss-security/2011/03/10/2http://openwall.com/lists/oss-security/2011/03/10/3http://openwall.com/lists/oss-security/2011/03/10/6http://openwall.com/lists/oss-security/2011/03/10/7http://openwall.com/lists/oss-security/2011/03/11/3http://openwall.com/lists/oss-security/2011/03/11/5http://openwall.com/lists/oss-security/2011/03/14/26http://openwall.com/lists/oss-security/2011/03/23/11http://secunia.com/advisories/43955http://www.mandriva.com/security/advisories?name=MDVSA-2011:065http://www.redhat.com/support/errata/RHSA-2011-0407.htmlhttp://www.vupen.com/english/advisories/2011/0791http://www.vupen.com/english/advisories/2011/0872http://www.vupen.com/english/advisories/2011/0961https://bugzilla.redhat.com/show_bug.cgi?id=680798
2011-03-30
Published