Source: logrotate
Version: 3.18.1-2
Severity: important
Tags: security upstream
Forwarded: https://github.com/logrotate/logrotate/pull/427
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: found -1 3.18.0-2
Control: found -1 3.14.0-4

Hi

Background for this hardening for logrotate is from
https://www.openwall.com/lists/oss-security/2021/10/20/2 .
See the upstream issue
https://github.com/logrotate/logrotate/pull/427, but I suggest to wait
until the changes are commited.

Later on after some expure, it might be worth making the fixes as well
available to stable and older via point releases.

Regards,
Salvatore

-- System Information:
Debian Release: bookworm/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 5.16.0-rc3-amd64 (SMP w/8 CPU threads; PREEMPT)
Locale: LANG=C.UTF-8, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Reply via email to