Ubuntu 8.04 LTS / 10.04 LTS / 10.10 / 11.04 : logrotate vulnerabilities (USN-1172-1)

Ubuntu Security Notice (C) 2011-2016 Canonical, Inc. / NASL script (C) 2011-2016 Tenable Network Security, Inc.


Synopsis :

The remote Ubuntu host is missing a security-related patch.

Description :

It was discovered that logrotate incorrectly handled the creation of
new log files. Local users could possibly read log files if they were
opened before permissions were in place. This issue only affected
Ubuntu 8.04 LTS. (CVE-2011-1098)

It was discovered that logrotate incorrectly handled certain log file
names when used with the shred option. Local attackers able to create
log files with specially crafted filenames could use this issue to
execute arbitrary code. This issue only affected Ubuntu 10.04 LTS,
10.10, and 11.04. (CVE-2011-1154)

It was discovered that logrotate incorrectly handled certain malformed
log filenames. Local attackers able to create log files with specially
crafted filenames could use this issue to cause logrotate to stop
processing log files, resulting in a denial of service.
(CVE-2011-1155)

It was discovered that logrotate incorrectly handled symlinks and hard
links when processing log files. A local attacker having write access
to a log file directory could use this issue to overwrite or read
arbitrary files. This issue only affected Ubuntu 8.04 LTS.
(CVE-2011-1548).

Note that Tenable Network Security has extracted the preceding
description block directly from the Ubuntu security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

Solution :

Update the affected logrotate package.

Risk factor :

Medium / CVSS Base Score : 6.9
(CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 5.7
(CVSS2#E:F/RL:OF/RC:ND)
Public Exploit Available : true

Family: Ubuntu Local Security Checks

Nessus Plugin ID: 55648 ()

Bugtraq ID: 47103
47107
47108
47167

CVE ID: CVE-2011-1098
CVE-2011-1154
CVE-2011-1155
CVE-2011-1548