QID 354373
Date Published: 2022-12-21
QID 354373: Amazon Linux Security Advisory for logrotate : ALAS2022-2022-084
A vulnerability was found in logrotate in how the state file is created.
The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock.
When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation.
This flaw affects logrotate versions before 3.20.0. (
( CVE-2022-1348)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
Solution
Please refer to Amazon advisory: ALAS2022-2022-084 for affected packages and patching details, or update with your package manager.
Vendor References
- ALAS2022-2022-084 -
alas.aws.amazon.com/AL2022/ALAS-2022-084.html
CVEs related to QID 354373
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2022-2022-084 | amazon linux 2022 |
|