Mandriva Linux Security Advisory : logrotate (MDVSA-2011:065)

medium Nessus Plugin ID 53301

Synopsis

The remote Mandriva Linux host is missing a security update.

Description

Multiple vulnerabilities were discovered and corrected in logrotate :

Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the intended permissions are in place (CVE-2011-1098).

The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name (CVE-2011-1154).

The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash) character in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name (CVE-2011-1155).

Packages for 2009.0 are provided as of the Extended Maintenance Program. Please visit this link to learn more:
http://store.mandriva.com/product_info.php?cPath=149 products_id=490

The updated packages have been upgraded to the 3.7.9 version and patched to correct these issues.

Solution

Update the affected logrotate package.

Plugin Details

Severity: Medium

ID: 53301

File Name: mandriva_MDVSA-2011-065.nasl

Version: 1.11

Type: local

Published: 4/6/2011

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.9

Temporal Score: 5.1

Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/o:mandriva:linux:2009.0, cpe:/o:mandriva:linux:2010.0, cpe:/o:mandriva:linux:2010.1, p-cpe:/a:mandriva:linux:logrotate

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 4/5/2011

Reference Information

CVE: CVE-2011-1098, CVE-2011-1154, CVE-2011-1155

BID: 47103, 47107, 47108

MDVSA: 2011:065