Ubuntu Security Notice (C) 2011-2016 Canonical, Inc. / NASL script (C) 2011-2016 Tenable Network Security, Inc.
The remote Ubuntu host is missing a security-related patch.
It was discovered that logrotate incorrectly handled the creation of
new log files. Local users could possibly read log files if they were
opened before permissions were in place. This issue only affected
Ubuntu 8.04 LTS. (CVE-2011-1098)
It was discovered that logrotate incorrectly handled certain log file
names when used with the shred option. Local attackers able to create
log files with specially crafted filenames could use this issue to
execute arbitrary code. This issue only affected Ubuntu 10.04 LTS,
10.10, and 11.04. (CVE-2011-1154)
It was discovered that logrotate incorrectly handled certain malformed
log filenames. Local attackers able to create log files with specially
crafted filenames could use this issue to cause logrotate to stop
processing log files, resulting in a denial of service.
It was discovered that logrotate incorrectly handled symlinks and hard
links when processing log files. A local attacker having write access
to a log file directory could use this issue to overwrite or read
arbitrary files. This issue only affected Ubuntu 8.04 LTS.
Note that Tenable Network Security has extracted the preceding
description block directly from the Ubuntu security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.
Update the affected logrotate package.
Risk factor :
Medium / CVSS Base Score : 6.9
CVSS Temporal Score : 5.7
Public Exploit Available : true
Family: Ubuntu Local Security Checks
Nessus Plugin ID: 55648 ()
Bugtraq ID: 47103471074710847167
CVE ID: CVE-2011-1098CVE-2011-1154CVE-2011-1155CVE-2011-1548
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.