Lucene search

K
cveMitreCVE-2011-1549
HistoryMar 30, 2011 - 10:55 p.m.

CVE-2011-1549

2011-03-3022:55:02
CWE-264
mitre
web.nvd.nist.gov
33
gentoo linux
logrotate
cve-2011-1549
symlink attacks
hard link attacks
nvd
privilege escalation
security vulnerability
logrotate configuration

CVSS2

6.3

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:C/A:C

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

10.1%

The default configuration of logrotate on Gentoo Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate’s lack of support for untrusted directories, as demonstrated by directories under /var/log/ for packages.

Affected configurations

Nvd
Node
gentoologrotate
AND
gentoolinux
VendorProductVersionCPE
gentoologrotate*cpe:2.3:a:gentoo:logrotate:*:*:*:*:*:*:*:*
gentoolinux*cpe:2.3:o:gentoo:linux:*:*:*:*:*:*:*:*

References

CVSS2

6.3

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:C/A:C

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

10.1%