Source: logrotate Version: 3.18.1-2 Severity: important Tags: security upstream Forwarded: https://github.com/logrotate/logrotate/pull/427 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]> Control: found -1 3.18.0-2 Control: found -1 3.14.0-4
Hi Background for this hardening for logrotate is from https://www.openwall.com/lists/oss-security/2021/10/20/2 . See the upstream issue https://github.com/logrotate/logrotate/pull/427, but I suggest to wait until the changes are commited. Later on after some expure, it might be worth making the fixes as well available to stable and older via point releases. Regards, Salvatore -- System Information: Debian Release: bookworm/sid APT prefers unstable APT policy: (500, 'unstable'), (1, 'experimental') Architecture: amd64 (x86_64) Kernel: Linux 5.16.0-rc3-amd64 (SMP w/8 CPU threads; PREEMPT) Locale: LANG=C.UTF-8, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE not set Shell: /bin/sh linked to /usr/bin/dash Init: systemd (via /run/systemd/system) LSM: AppArmor: enabled

