CVE-2011-1550

N/A Unknown
Published: March 30, 2011 Modified: April 29, 2026
View on NVD

Description

The default configuration of logrotate on SUSE openSUSE Factory uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by directories for the (1) cobbler, (2) inn, (3) safte-monitor, and (4) uucp packages.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://openwall.com/lists/oss-security/2011/03/04/16
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/04/17
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/04/18
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/04/19
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/04/22
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/04/24
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/04/25
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/04/26
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/04/27
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/04/28
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/04/29
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/04/30
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/04/31
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/04/32
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/04/33
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/05/4
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/05/6
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/05/8
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/06/3
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/06/4
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/06/5
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/06/6
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/07/11
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/07/5
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/07/6
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/08/5
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/10/2
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/10/3
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/10/6
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/10/7
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/11/3
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/11/5
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/14/26
Source: af854a3a-2127-422b-91ae-364da2661108
http://openwall.com/lists/oss-security/2011/03/23/11
Source: af854a3a-2127-422b-91ae-364da2661108

68 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
0.4%
27th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

novell gentoo