Local File Processing Vulnerability in Debian GNU/Linux Logrotate
CVE-2011-1548
Currently unrated
What is CVE-2011-1548?
The default configuration of logrotate in Debian GNU/Linux grants root privileges to process log files within directories that allow non-root users to write. This design flaw exposes the system to symlink and hard link attacks, enabling local users to manipulate log files. As exemplified by PostgreSQL log files under /var/log/postgresql/, untrusted directories lack the adequate safeguards to prevent exploitation. Administrators should review and tighten permissions and configurations to mitigate risks associated with this vulnerability.