]> code.ossystems Code Review - openembedded-core.git/commit
logrotate: fix for CVE-2011-1548
authorWenzong Fan <wenzong.fan@windriver.com>
Tue, 18 Jun 2013 02:28:50 +0000 (22:28 -0400)
committerPaul Eggleton <paul.eggleton@linux.intel.com>
Mon, 8 Jul 2013 09:30:21 +0000 (10:30 +0100)
commit247157849f41f2d386b102a4b3d81fd11e8f3ac0
tree3a161a7a3c8d92eb9eba3bf7f1b5b525c4372fc0
parent1b9b8be17937548135b4c93fc9753c7bd4fc5fbd
logrotate: fix for CVE-2011-1548

If a logfile is a symlink, it may be read when being compressed, being
copied (copy, copytruncate) or mailed. Secure data (eg. password files)
may be exposed.

Portback nofollow.patch from:
http://logrotate.sourcearchive.com/downloads/3.8.1-5/logrotate_3.8.1-5.debian.tar.gz

(From OE-Core master rev: d0e3fc1b28fc16200adbe690aa27124041036ba3)

Signed-off-by: Wenzong Fan <wenzong.fan@windriver.com>
Signed-off-by: Saul Wold <sgw@linux.intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-extended/logrotate/logrotate-3.8.1/logrotate-CVE-2011-1548.patch [new file with mode: 0644]
meta/recipes-extended/logrotate/logrotate_3.8.1.bb