Ubuntu 8.04 LTS / 10.04 LTS / 10.10 / 11.04 : logrotate vulnerabilities (USN-1172-1)

Ubuntu Security Notice (C) 2011-2013 Canonical, Inc. / NASL script (C) 2011-2013 Tenable Network Security, Inc.


Synopsis :

The remote Ubuntu host is missing a security-related patch.

Description :

It was discovered that logrotate incorrectly handled the creation of
new log files. Local users could possibly read log files if they were
opened before permissions were in place. This issue only affected
Ubuntu 8.04 LTS. (CVE-2011-1098)

It was discovered that logrotate incorrectly handled certain log file
names when used with the shred option. Local attackers able to create
log files with specially crafted filenames could use this issue to
execute arbitrary code. This issue only affected Ubuntu 10.04 LTS,
10.10, and 11.04. (CVE-2011-1154)

It was discovered that logrotate incorrectly handled certain malformed
log filenames. Local attackers able to create log files with specially
crafted filenames could use this issue to cause logrotate to stop
processing log files, resulting in a denial of service.
(CVE-2011-1155)

It was discovered that logrotate incorrectly handled symlinks and hard
links when processing log files. A local attacker having write access
to a log file directory could use this issue to overwrite or read
arbitrary files. This issue only affected Ubuntu 8.04 LTS.
(CVE-2011-1548).

Solution :

Update the affected logrotate package.

Risk factor :

Medium / CVSS Base Score : 6.9
(CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 5.7
(CVSS2#E:F/RL:OF/RC:ND)
Public Exploit Available : true

Family: Ubuntu Local Security Checks

Nessus Plugin ID: 55648 ()

Bugtraq ID: 47103
47107
47108
47167

CVE ID: CVE-2011-1098
CVE-2011-1154
CVE-2011-1155
CVE-2011-1548