CVE-2011-1155

Impact:
Low
Public Date:
2011-02-13
Bugzilla:
680797: CVE-2011-1155 logrotate: DoS due improper escaping of file names within 'write state' action

The MITRE CVE dictionary describes this issue as:

The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash) character in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.

Find out more about CVE-2011-1155 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.

CVSS v2 metrics

Base Score 1.9
Base Metrics AV:L/AC:M/Au:N/C:N/I:N/A:P
Access Vector Local
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 6 (logrotate) RHSA-2011:0407 2011-03-31

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 5 logrotate Will not fix
Red Hat Enterprise Linux 4 logrotate Will not fix

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.