CVE-2019-11675

NameCVE-2019-11675
DescriptionThe groonga-httpd package 6.1.5-1 for Debian sets the /var/log/groonga ownership to the groonga account, which might let local users obtain root access because of unsafe interaction with logrotate. For example, an attacker can exploit a race condition to insert a symlink from /var/log/groonga/httpd to /etc/bash_completion.d. NOTE: this is an issue in the Debian packaging of the Groonga HTTP server.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs928304

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
groonga (PTS)buster9.0.0-1+deb10u1fixed
bullseye11.0.0-2fixed
bookworm13.0.0+dfsg-3~deb12u1fixed
trixie13.1.1+dfsg-1fixed
sid13.1.1+dfsg-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
groongasourcestretch6.1.5-1+deb9u1
groongasourcebuster9.0.0-1+deb10u1
groongasource(unstable)9.0.1-2928304

Search for package or bug name: Reporting problems