QID 354465

Date Published: 2022-12-21

QID 354465: Amazon Linux Security Advisory for logrotate : ALAS2022-2022-189

A vulnerability was found in logrotate in how the state file is created.
The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock.
When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation.
This flaw affects logrotate versions before 3.20.0. (
( CVE-2022-1348)



Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Please refer to Amazon advisory: ALAS2022-2022-189 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 354465

    Software Advisories
    Advisory ID Software Component Link
    ALAS2022-2022-189 amazon linux 2022 URL Logo alas.aws.amazon.com/AL2022/ALAS-2022-189.html