cbcvebase.
CVE-2011-1548
published 2011-03-30

CVE-2011-1548: The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, which allows…

PriorityP421medium6.3CVSS 2.0
AVLACMAuNCNICAC
EPSS
0.39%
31.2th percentile
The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by /var/log/postgresql/.

Affected

5 ranges
VendorProductVersion rangeFixed in
debianlogrotate< logrotate 3.7.8-6 (bookworm)logrotate 3.7.8-6 (bookworm)
logrotate_projectlogrotate>= 0 < 3.7.8-63.7.8-6
logrotate_projectlogrotate>= 0 < 3.7.8-63.7.8-6
logrotate_projectlogrotate>= 0 < 3.7.8-63.7.8-6
logrotate_projectlogrotate>= 0 < 3.7.8-63.7.8-6

CVSS provenance

nvdv2.06.3MEDIUMAV:L/AC:M/Au:N/C:N/I:C/A:C
osv6.3MEDIUM
vendor_debian6.3MEDIUM
vendor_ubuntu1.9LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.