CVE-2011-1155
published 2011-03-30CVE-2011-1155: The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage)…
PriorityP47low1.9CVSS 2.0
AVLACMAuNCNINAP
EPSS
0.39%
30.9th percentile
The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash) character in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | logrotate | < logrotate 3.8.0-1 (bookworm) | logrotate 3.8.0-1 (bookworm) |
| gentoo | logrotate | <= 3.7.9 | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| gentoo | logrotate | — | — |
| logrotate_project | logrotate | >= 0 < 3.8.0-1 | 3.8.0-1 |
| logrotate_project | logrotate | >= 0 < 3.8.0-1 | 3.8.0-1 |
| logrotate_project | logrotate | >= 0 < 3.8.0-1 | 3.8.0-1 |
| logrotate_project | logrotate | >= 0 < 3.8.0-1 | 3.8.0-1 |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv1.9LOW
vendor_debian1.9LOW
vendor_redhat1.9LOW
vendor_ubuntu1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
logrotate vulnerabilities
vendor_ubuntu·2011-07-21·CVSS 1.9
CVE-2011-1098 [LOW] logrotate vulnerabilities
Title: logrotate vulnerabilities
Summary: An attacker could cause logrotate to run programs, stop working, or read
and write arbitrary files.
It was discovered that logrotate incorrectly handled the creation of new
log files. Local users could possibly read log files if they were opened
before permissions were in place. This issue only affected Ubuntu 8.04 LTS.
(CVE-2011-1098)
It was discovered that logrotate incorrectly handled certain log file
names when used with the shred option. Local attackers able to create log
files with specially crafted filenames could use this issue to execute
arbitrary code. This issue only affected Ubuntu 10.04 LTS, 10.10, and
11.04. (CVE-2011-1154)
It was discovered that logrotate incorrectly handled certain malformed log
filenames. Local attackers able t
Red Hat
logrotate: DoS due improper escaping of file names within 'write state' action
vendor_redhat·2011-02-13·CVSS 1.9
CVE-2011-1155 [LOW] logrotate: DoS due improper escaping of file names within 'write state' action
logrotate: DoS due improper escaping of file names within 'write state' action
The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash) character in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.
Statement: The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.
Package: logrotate (Red Hat Enterprise Linux 4) - Will not fix
Package: logrotate (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2011-1155: logrotate - The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allo...
vendor_debian·2011·CVSS 1.9
CVE-2011-1155 [LOW] CVE-2011-1155: logrotate - The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allo...
The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash) character in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.
Scope: local
bookworm: resolved (fixed in 3.8.0-1)
bullseye: resolved (fixed in 3.8.0-1)
forky: resolved (fixed in 3.8.0-1)
sid: resolved (fixed in 3.8.0-1)
trixie: resolved (fixed in 3.8.0-1)
GHSA
GHSA-fcm8-m55c-7v4r: The writeState function in logrotate
ghsa_unreviewed·2022-05-17
CVE-2011-1155 [LOW] GHSA-fcm8-m55c-7v4r: The writeState function in logrotate
The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash) character in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.
OSV
CVE-2011-1155: The writeState function in logrotate
osv·2011-03-30·CVSS 1.9
CVE-2011-1155 [LOW] CVE-2011-1155: The writeState function in logrotate
The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash) character in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1098 CVE-2011-1154 CVE-2011-1155 logrotate various flaws [fedora-all]
bugzilla·2011-03-17·CVSS 1.9
CVE-2011-1098 [LOW] CVE-2011-1098 CVE-2011-1154 CVE-2011-1155 logrotate various flaws [fedora-all]
CVE-2011-1098 CVE-2011-1154 CVE-2011-1155 logrotate various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=680798
Please note: this issue affects mult
Bugzilla
CVE-2011-1155 logrotate: DoS due improper escaping of file names within 'write state' action
bugzilla·2011-02-27·CVSS 1.9
CVE-2011-1155 [LOW] CVE-2011-1155 logrotate: DoS due improper escaping of file names within 'write state' action
CVE-2011-1155 logrotate: DoS due improper escaping of file names within 'write state' action
A denial of service flaw was found in the way the logrotate utility
performed arguments sanitization, when performing the 'write state'
action. A local attacker could use this flaw to cause abort in
subsequent logrotate runs via a specially-crafted log file name.
Discussion:
Created attachment 481603
proposed patch
This patch fixes the bug by escaping line-feed and backslash and by using 2 * PATH_MAX + 16 for buffer size if PATH_MAX is defined.
---
Created logrotate tracking bugs for this issue
Affects: fedora-all [bug 688520]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0407 https://rhn.redhat.com/errata/RHSA-2011-0407.html
---
Stat
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057845.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056992.htmlhttp://openwall.com/lists/oss-security/2011/03/04/16http://openwall.com/lists/oss-security/2011/03/04/17http://openwall.com/lists/oss-security/2011/03/04/18http://openwall.com/lists/oss-security/2011/03/04/19http://openwall.com/lists/oss-security/2011/03/04/22http://openwall.com/lists/oss-security/2011/03/04/24http://openwall.com/lists/oss-security/2011/03/04/25http://openwall.com/lists/oss-security/2011/03/04/26http://openwall.com/lists/oss-security/2011/03/04/27http://openwall.com/lists/oss-security/2011/03/04/28http://openwall.com/lists/oss-security/2011/03/04/29http://openwall.com/lists/oss-security/2011/03/04/30http://openwall.com/lists/oss-security/2011/03/04/31http://openwall.com/lists/oss-security/2011/03/04/32http://openwall.com/lists/oss-security/2011/03/04/33http://openwall.com/lists/oss-security/2011/03/05/4http://openwall.com/lists/oss-security/2011/03/05/6http://openwall.com/lists/oss-security/2011/03/05/8http://openwall.com/lists/oss-security/2011/03/06/3http://openwall.com/lists/oss-security/2011/03/06/4http://openwall.com/lists/oss-security/2011/03/06/5http://openwall.com/lists/oss-security/2011/03/06/6http://openwall.com/lists/oss-security/2011/03/07/11http://openwall.com/lists/oss-security/2011/03/07/5http://openwall.com/lists/oss-security/2011/03/07/6http://openwall.com/lists/oss-security/2011/03/08/5http://openwall.com/lists/oss-security/2011/03/10/2http://openwall.com/lists/oss-security/2011/03/10/3http://openwall.com/lists/oss-security/2011/03/10/6http://openwall.com/lists/oss-security/2011/03/10/7http://openwall.com/lists/oss-security/2011/03/11/3http://openwall.com/lists/oss-security/2011/03/11/5http://openwall.com/lists/oss-security/2011/03/14/26http://openwall.com/lists/oss-security/2011/03/23/11http://secunia.com/advisories/43955http://www.mandriva.com/security/advisories?name=MDVSA-2011:065http://www.redhat.com/support/errata/RHSA-2011-0407.htmlhttp://www.vupen.com/english/advisories/2011/0791http://www.vupen.com/english/advisories/2011/0872http://www.vupen.com/english/advisories/2011/0961https://bugzilla.redhat.com/show_bug.cgi?id=680797http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057845.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056992.htmlhttp://openwall.com/lists/oss-security/2011/03/04/16http://openwall.com/lists/oss-security/2011/03/04/17http://openwall.com/lists/oss-security/2011/03/04/18http://openwall.com/lists/oss-security/2011/03/04/19http://openwall.com/lists/oss-security/2011/03/04/22http://openwall.com/lists/oss-security/2011/03/04/24http://openwall.com/lists/oss-security/2011/03/04/25http://openwall.com/lists/oss-security/2011/03/04/26http://openwall.com/lists/oss-security/2011/03/04/27http://openwall.com/lists/oss-security/2011/03/04/28http://openwall.com/lists/oss-security/2011/03/04/29http://openwall.com/lists/oss-security/2011/03/04/30http://openwall.com/lists/oss-security/2011/03/04/31http://openwall.com/lists/oss-security/2011/03/04/32http://openwall.com/lists/oss-security/2011/03/04/33http://openwall.com/lists/oss-security/2011/03/05/4http://openwall.com/lists/oss-security/2011/03/05/6http://openwall.com/lists/oss-security/2011/03/05/8http://openwall.com/lists/oss-security/2011/03/06/3http://openwall.com/lists/oss-security/2011/03/06/4http://openwall.com/lists/oss-security/2011/03/06/5http://openwall.com/lists/oss-security/2011/03/06/6http://openwall.com/lists/oss-security/2011/03/07/11http://openwall.com/lists/oss-security/2011/03/07/5http://openwall.com/lists/oss-security/2011/03/07/6http://openwall.com/lists/oss-security/2011/03/08/5http://openwall.com/lists/oss-security/2011/03/10/2http://openwall.com/lists/oss-security/2011/03/10/3http://openwall.com/lists/oss-security/2011/03/10/6http://openwall.com/lists/oss-security/2011/03/10/7http://openwall.com/lists/oss-security/2011/03/11/3http://openwall.com/lists/oss-security/2011/03/11/5http://openwall.com/lists/oss-security/2011/03/14/26http://openwall.com/lists/oss-security/2011/03/23/11http://secunia.com/advisories/43955http://www.mandriva.com/security/advisories?name=MDVSA-2011:065http://www.redhat.com/support/errata/RHSA-2011-0407.htmlhttp://www.vupen.com/english/advisories/2011/0791http://www.vupen.com/english/advisories/2011/0872http://www.vupen.com/english/advisories/2011/0961https://bugzilla.redhat.com/show_bug.cgi?id=680797
2011-03-30
Published