Logo
componentlogrotate
Name
logrotate
Version
3.22.0
Type
library
Description
Rotates, compresses, removes and mails system log files
Licenses
GPL-2.0-only
PURL
-
CPE
cpe:2.3:*:logrotate_project:logrotate:3.22.0:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
kirkstone
3.20.1
scarthgap
3.21.0

Patches#


#
Title
Author
Resolve
1
test: avoid locale dependent errno string
=?UTF-8?q?Christian=20G=C3=B6ttsche?= <cgzones@googlemail.com>

Vulnerabilities#


Name
Analysis
Description
False Positive
The default configuration of logrotate on SUSE openSUSE Factory uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by directories for the (1) cobbler, (2) inn, (3) safte-monitor, and (4) uucp packages.
False Positive
The default configuration of logrotate on Gentoo Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by directories under /var/log/ for packages.
False Positive
The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by /var/log/postgresql/.