CVE-2011-1548

EPSS 0.06%
Published: 3/30/2011Modified: 4/28/2026
Also known as:DEBIAN-CVE-2011-1548

Description

The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by /var/log/postgresql/.

Affected packages (1)

References (1)