Bug 680796 (CVE-2011-1154) - CVE-2011-1154 logrotate: Shell command injection by using the shred configuration directive
Summary: CVE-2011-1154 logrotate: Shell command injection by using the shred configura...
Status: CLOSED ERRATA
Alias: CVE-2011-1154
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: public=20110213,reported=20110213,sou...
Keywords: Reopened, Security
Depends On: 688518 688519 688520
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-02-27 19:36 UTC by Jan Lieskovsky
Modified: 2019-06-08 18:45 UTC (History)
4 users (show)

(edit)
Clone Of:
(edit)
Last Closed: 2015-07-29 14:03:09 UTC


Attachments (Terms of Use)
proposed patch (3.61 KB, patch)
2011-02-28 10:06 UTC, Jan Kaluža
no flags Details | Diff
proposed patch (3.72 KB, patch)
2011-03-01 08:41 UTC, Jan Kaluža
no flags Details | Diff


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2011:0407 normal SHIPPED_LIVE Moderate: logrotate security update 2011-03-31 15:16:26 UTC

Description Jan Lieskovsky 2011-02-27 19:36:26 UTC
A shell command injection flaw was found in the way the logrotate utility
handled shred configuration directive (intended to ensure the log files
are not readable after their scheduled deletion). A local attacker could
use this flaw to execute arbitrary system commands (if the logrotate
was run under privileged system user account, root) when the logrotate
utility was run on a log file, within attacker controllable directory.

Comment 1 Jan Kaluža 2011-02-28 10:06:10 UTC
Created attachment 481342 [details]
proposed patch

Fixes mentioned bug by passing file descriptor as STDOUT to shred utility instead of passing filename. Any feedback is welcome.

Comment 5 Jan Kaluža 2011-03-01 08:41:31 UTC
Created attachment 481556 [details]
proposed patch

This patch also unlinks log file after shredding.

Comment 7 Huzaifa S. Sidhpurwala 2011-03-17 09:58:06 UTC
Created logrotate tracking bugs for this issue

Affects: fedora-all [bug 688520]

Comment 8 errata-xmlrpc 2011-03-31 15:16:32 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2011:0407 https://rhn.redhat.com/errata/RHSA-2011-0407.html

Comment 9 Jan Lieskovsky 2011-03-31 15:34:14 UTC
Statement:

Not vulnerable. This issue did not affect the versions of logrotate as
shipped with Red Hat Enterprise Linux 4 and 5, as they did not support
'shred' logrotate configuration directive yet.


Note You need to log in before you can comment on or make changes to this bug.