logrotate: fix for CVE-2011-1548
authorWenzong Fan <wenzong.fan@windriver.com>
Tue, 18 Jun 2013 02:28:50 +0000 (22:28 -0400)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Tue, 25 Jun 2013 16:44:55 +0000 (17:44 +0100)
commitcac8d360e3e32969c507e8c6cb2e6a091010b0f2
tree1a62637113af2436edf48f8a36e4fd82e4a3abdf
parent7f52953c02f3ac21ae7e475e79b5d088ed30ae63
logrotate: fix for CVE-2011-1548

If a logfile is a symlink, it may be read when being compressed, being
copied (copy, copytruncate) or mailed. Secure data (eg. password files)
may be exposed.

Portback nofollow.patch from:
http://logrotate.sourcearchive.com/downloads/3.8.1-5/logrotate_3.8.1-5.debian.tar.gz

(From OE-Core rev: d0e3fc1b28fc16200adbe690aa27124041036ba3)

Signed-off-by: Wenzong Fan <wenzong.fan@windriver.com>
Signed-off-by: Saul Wold <sgw@linux.intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-extended/logrotate/logrotate-3.8.1/logrotate-CVE-2011-1548.patch [new file with mode: 0644]
meta/recipes-extended/logrotate/logrotate_3.8.1.bb