VYPR
Unrated severityNVD Advisory· Published Mar 30, 2011· Updated Apr 29, 2026

CVE-2011-1155

CVE-2011-1155

Description

The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash) character in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.

Affected products

14
  • Gentoo/Logrotate14 versions
    cpe:2.3:a:gentoo:logrotate:*:*:*:*:*:*:*:*+ 13 more
    • cpe:2.3:a:gentoo:logrotate:*:*:*:*:*:*:*:*range: <=3.7.9
    • cpe:2.3:a:gentoo:logrotate:3.3:r2:*:*:*:*:*:*
    • cpe:2.3:a:gentoo:logrotate:3.5.9:*:*:*:*:*:*:*
    • cpe:2.3:a:gentoo:logrotate:3.5.9:r1:*:*:*:*:*:*
    • cpe:2.3:a:gentoo:logrotate:3.6.5:*:*:*:*:*:*:*
    • cpe:2.3:a:gentoo:logrotate:3.6.5:r1:*:*:*:*:*:*
    • cpe:2.3:a:gentoo:logrotate:3.7:*:*:*:*:*:*:*
    • cpe:2.3:a:gentoo:logrotate:3.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gentoo:logrotate:3.7.1:r1:*:*:*:*:*:*
    • cpe:2.3:a:gentoo:logrotate:3.7.1:r2:*:*:*:*:*:*
    • cpe:2.3:a:gentoo:logrotate:3.7.2:*:*:*:*:*:*:*
    • cpe:2.3:a:gentoo:logrotate:3.7.6:*:*:*:*:*:*:*
    • cpe:2.3:a:gentoo:logrotate:3.7.7:*:*:*:*:*:*:*
    • cpe:2.3:a:gentoo:logrotate:3.7.8:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

43

News mentions

0

No linked articles in our index yet.