Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the intended permissions are in place.
| Software | From | Fixed in |
|---|---|---|
| gentoo / logrotate | 3.6.5 | 3.6.5.x |
| gentoo / logrotate | 3.7.8 | 3.7.8.x |
| gentoo / logrotate | 3.5.9-r1 | 3.5.9-r1.x |
| gentoo / logrotate | 3.7.6 | 3.7.6.x |
| gentoo / logrotate | 3.3-r2 | 3.3-r2.x |
| gentoo / logrotate | 3.7.2 | 3.7.2.x |
| gentoo / logrotate | 3.7 | 3.7.x |
| gentoo / logrotate | 3.7.1-r2 | 3.7.1-r2.x |
| gentoo / logrotate | 3.6.5-r1 | 3.6.5-r1.x |
| gentoo / logrotate | 3.5.9 | 3.5.9.x |
| gentoo / logrotate | 3.7.1-r1 | 3.7.1-r1.x |
| gentoo / logrotate | - | 3.7.9.x |
| gentoo / logrotate | 3.7.1 | 3.7.1.x |
| gentoo / logrotate | 3.7.7 | 3.7.7.x |