CVE-2011-1098

EUVD-2011-1112
Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the intended permissions are in place.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
1.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
Affected Products (NVD)
VendorProductVersion
gentoologrotate
𝑥
≤ 3.7.9
gentoologrotate
3.3:r2
gentoologrotate
3.5.9
gentoologrotate
3.5.9:r1
gentoologrotate
3.6.5
gentoologrotate
3.6.5:r1
gentoologrotate
3.7
gentoologrotate
3.7.1
gentoologrotate
3.7.1:r1
gentoologrotate
3.7.1:r2
gentoologrotate
3.7.2
gentoologrotate
3.7.6
gentoologrotate
3.7.7
gentoologrotate
3.7.8
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
logrotate
bookworm
3.21.0-1
fixed
bullseye
3.18.0-2+deb11u2
fixed
sid
3.22.0-1
fixed
squeeze
no-dsa
trixie
3.22.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
logrotate
dapper
ignored
hardy
Fixed 3.7.1-3ubuntu0.8.04.1
released
karmic
ignored
lucid
not-affected
maverick
not-affected
natty
not-affected
References