Oval Definition:oval:com.redhat.rhsa:def:20110407
Revision Date:2011-03-31Version:643
Title:RHSA-2011:0407: logrotate security update (Moderate)
Description:The logrotate utility simplifies the administration of multiple log files, allowing the automatic rotation, compression, removal, and mailing of log files.

  • A shell command injection flaw was found in the way logrotate handled the shred directive. A specially-crafted log file could cause logrotate to execute arbitrary commands with the privileges of the user running logrotate (root, by default). Note: The shred directive is not enabled by default. (CVE-2011-1154)

  • A race condition flaw was found in the way logrotate applied permissions when creating new log files. In some specific configurations, a local attacker could use this flaw to open new log files before logrotate applies the final permissions, possibly leading to the disclosure of sensitive information. (CVE-2011-1098)

  • An input sanitization flaw was found in logrotate. A log file with a specially-crafted file name could cause logrotate to abort when attempting to process that file a subsequent time. (CVE-2011-1155)

    All logrotate users should upgrade to this updated package, which contains backported patches to resolve these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2011-1098
    CVE-2011-1098
    CVE-2011-1154
    CVE-2011-1154
    CVE-2011-1155
    CVE-2011-1155
    RHSA-2011:0407
    RHSA-2011:0407-01
    RHSA-2011:0407-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND logrotate is earlier than 0:3.7.8-12.el6_0.1
  • AND logrotate is signed with Red Hat redhatrelease2 key
  • BACK