CVE-2011-1154
published 2011-03-30CVE-2011-1154: The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell…
PriorityP433medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.41%
33.9th percentile
The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | logrotate | < logrotate 3.8.0-1 (bookworm) | logrotate 3.8.0-1 (bookworm) |
| gentoo | logrotate | <= 3.7.9 | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| logrotate_project | logrotate | >= 0 < 3.8.0-1 | 3.8.0-1 |
| logrotate_project | logrotate | >= 0 < 3.8.0-1 | 3.8.0-1 |
| logrotate_project | logrotate | >= 0 < 3.8.0-1 | 3.8.0-1 |
| logrotate_project | logrotate | >= 0 < 3.8.0-1 | 3.8.0-1 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
vendor_ubuntu1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-57xq-cfp9-365f: The shred_file function in logrotate
ghsa_unreviewed·2022-05-17
CVE-2011-1154 [MEDIUM] CWE-20 GHSA-57xq-cfp9-365f: The shred_file function in logrotate
The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.
OSV
CVE-2011-1154: The shred_file function in logrotate
osv·2011-03-30·CVSS 6.9
CVE-2011-1154 [MEDIUM] CVE-2011-1154: The shred_file function in logrotate
The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.
Ubuntu
logrotate vulnerabilities
vendor_ubuntu·2011-07-21·CVSS 1.9
CVE-2011-1098 [LOW] logrotate vulnerabilities
Title: logrotate vulnerabilities
Summary: An attacker could cause logrotate to run programs, stop working, or read
and write arbitrary files.
It was discovered that logrotate incorrectly handled the creation of new
log files. Local users could possibly read log files if they were opened
before permissions were in place. This issue only affected Ubuntu 8.04 LTS.
(CVE-2011-1098)
It was discovered that logrotate incorrectly handled certain log file
names when used with the shred option. Local attackers able to create log
files with specially crafted filenames could use this issue to execute
arbitrary code. This issue only affected Ubuntu 10.04 LTS, 10.10, and
11.04. (CVE-2011-1154)
It was discovered that logrotate incorrectly handled certain malformed log
filenames. Local attackers able t
Red Hat
logrotate: Shell command injection by using the shred configuration directive
vendor_redhat·2011-02-13·CVSS 6.9
CVE-2011-1154 [MEDIUM] logrotate: Shell command injection by using the shred configuration directive
logrotate: Shell command injection by using the shred configuration directive
The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.
Statement: Not vulnerable. This issue did not affect the versions of logrotate as
shipped with Red Hat Enterprise Linux 4 and 5, as they did not support
'shred' logrotate configuration directive yet.
Package: logrotate (Red Hat Enterprise Linux 4) - Not affected
Package: logrotate (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2011-1154: logrotate - The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allo...
vendor_debian·2011·CVSS 6.9
CVE-2011-1154 [MEDIUM] CVE-2011-1154: logrotate - The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allo...
The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.
Scope: local
bookworm: resolved (fixed in 3.8.0-1)
bullseye: resolved (fixed in 3.8.0-1)
forky: resolved (fixed in 3.8.0-1)
sid: resolved (fixed in 3.8.0-1)
trixie: resolved (fixed in 3.8.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1098 CVE-2011-1154 CVE-2011-1155 logrotate various flaws [fedora-all]
bugzilla·2011-03-17·CVSS 1.9
CVE-2011-1098 [LOW] CVE-2011-1098 CVE-2011-1154 CVE-2011-1155 logrotate various flaws [fedora-all]
CVE-2011-1098 CVE-2011-1154 CVE-2011-1155 logrotate various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=680798
Please note: this issue affects mult
Bugzilla
CVE-2011-1154 logrotate: Shell command injection by using the shred configuration directive
bugzilla·2011-02-27·CVSS 6.9
CVE-2011-1154 [MEDIUM] CVE-2011-1154 logrotate: Shell command injection by using the shred configuration directive
CVE-2011-1154 logrotate: Shell command injection by using the shred configuration directive
A shell command injection flaw was found in the way the logrotate utility
handled shred configuration directive (intended to ensure the log files
are not readable after their scheduled deletion). A local attacker could
use this flaw to execute arbitrary system commands (if the logrotate
was run under privileged system user account, root) when the logrotate
utility was run on a log file, within attacker controllable directory.
Discussion:
Created attachment 481342
proposed patch
Fixes mentioned bug by passing file descriptor as STDOUT to shred utility instead of passing filename. Any feedback is welcome.
---
Created attachment 481556
proposed patch
This patch also unlinks log file after shredd
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057845.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056992.htmlhttp://openwall.com/lists/oss-security/2011/03/04/16http://openwall.com/lists/oss-security/2011/03/04/17http://openwall.com/lists/oss-security/2011/03/04/18http://openwall.com/lists/oss-security/2011/03/04/19http://openwall.com/lists/oss-security/2011/03/04/22http://openwall.com/lists/oss-security/2011/03/04/24http://openwall.com/lists/oss-security/2011/03/04/25http://openwall.com/lists/oss-security/2011/03/04/26http://openwall.com/lists/oss-security/2011/03/04/27http://openwall.com/lists/oss-security/2011/03/04/28http://openwall.com/lists/oss-security/2011/03/04/29http://openwall.com/lists/oss-security/2011/03/04/30http://openwall.com/lists/oss-security/2011/03/04/31http://openwall.com/lists/oss-security/2011/03/04/32http://openwall.com/lists/oss-security/2011/03/04/33http://openwall.com/lists/oss-security/2011/03/05/4http://openwall.com/lists/oss-security/2011/03/05/6http://openwall.com/lists/oss-security/2011/03/05/8http://openwall.com/lists/oss-security/2011/03/06/3http://openwall.com/lists/oss-security/2011/03/06/4http://openwall.com/lists/oss-security/2011/03/06/5http://openwall.com/lists/oss-security/2011/03/06/6http://openwall.com/lists/oss-security/2011/03/07/11http://openwall.com/lists/oss-security/2011/03/07/5http://openwall.com/lists/oss-security/2011/03/07/6http://openwall.com/lists/oss-security/2011/03/08/5http://openwall.com/lists/oss-security/2011/03/10/2http://openwall.com/lists/oss-security/2011/03/10/3http://openwall.com/lists/oss-security/2011/03/10/6http://openwall.com/lists/oss-security/2011/03/10/7http://openwall.com/lists/oss-security/2011/03/11/3http://openwall.com/lists/oss-security/2011/03/11/5http://openwall.com/lists/oss-security/2011/03/14/26http://openwall.com/lists/oss-security/2011/03/23/11http://secunia.com/advisories/43955http://www.mandriva.com/security/advisories?name=MDVSA-2011:065http://www.redhat.com/support/errata/RHSA-2011-0407.htmlhttp://www.vupen.com/english/advisories/2011/0791http://www.vupen.com/english/advisories/2011/0872http://www.vupen.com/english/advisories/2011/0961https://bugzilla.redhat.com/show_bug.cgi?id=680796http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057845.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056992.htmlhttp://openwall.com/lists/oss-security/2011/03/04/16http://openwall.com/lists/oss-security/2011/03/04/17http://openwall.com/lists/oss-security/2011/03/04/18http://openwall.com/lists/oss-security/2011/03/04/19http://openwall.com/lists/oss-security/2011/03/04/22http://openwall.com/lists/oss-security/2011/03/04/24http://openwall.com/lists/oss-security/2011/03/04/25http://openwall.com/lists/oss-security/2011/03/04/26http://openwall.com/lists/oss-security/2011/03/04/27http://openwall.com/lists/oss-security/2011/03/04/28http://openwall.com/lists/oss-security/2011/03/04/29http://openwall.com/lists/oss-security/2011/03/04/30http://openwall.com/lists/oss-security/2011/03/04/31http://openwall.com/lists/oss-security/2011/03/04/32http://openwall.com/lists/oss-security/2011/03/04/33http://openwall.com/lists/oss-security/2011/03/05/4http://openwall.com/lists/oss-security/2011/03/05/6http://openwall.com/lists/oss-security/2011/03/05/8http://openwall.com/lists/oss-security/2011/03/06/3http://openwall.com/lists/oss-security/2011/03/06/4http://openwall.com/lists/oss-security/2011/03/06/5http://openwall.com/lists/oss-security/2011/03/06/6http://openwall.com/lists/oss-security/2011/03/07/11http://openwall.com/lists/oss-security/2011/03/07/5http://openwall.com/lists/oss-security/2011/03/07/6http://openwall.com/lists/oss-security/2011/03/08/5http://openwall.com/lists/oss-security/2011/03/10/2http://openwall.com/lists/oss-security/2011/03/10/3http://openwall.com/lists/oss-security/2011/03/10/6http://openwall.com/lists/oss-security/2011/03/10/7http://openwall.com/lists/oss-security/2011/03/11/3http://openwall.com/lists/oss-security/2011/03/11/5http://openwall.com/lists/oss-security/2011/03/14/26http://openwall.com/lists/oss-security/2011/03/23/11http://secunia.com/advisories/43955http://www.mandriva.com/security/advisories?name=MDVSA-2011:065http://www.redhat.com/support/errata/RHSA-2011-0407.htmlhttp://www.vupen.com/english/advisories/2011/0791http://www.vupen.com/english/advisories/2011/0872http://www.vupen.com/english/advisories/2011/0961https://bugzilla.redhat.com/show_bug.cgi?id=680796
2011-03-30
Published