CVE-2022-1348 — Incorrect Permission Assignment in Project Logrotate
Severity
6.5MEDIUMNVD
EPSS
0.1%
top 70.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 25
Latest updateFeb 15
Description
A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation. This flaw affects logrotate versions before 3.20.0.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6
Affected Packages10 packages
Also affects: Fedora 35, 36
Patches
🔴Vulnerability Details
2📋Vendor Advisories
5Microsoft▶
A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock↗2022-05-10
Debian▶
CVE-2022-1348: logrotate - A vulnerability was found in logrotate in how the state file is created. The sta...↗2022