Back

HIGH

freeradius: privilege escalation due to insecure logrotate configuration

Published May 24, 2019

Description

It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has control of the radiusd user to escalate his privileges to root, by tricking logrotate into writing a radiusd-writable file to a directory normally inaccessible by the radiusd user. NOTE: the upstream software maintainer has stated "there is simply no way for anyone to gain privileges through this alleged issue."

Affected products

Remediation

Red Hat mitigation

Add `su radiusd:radiusd` to all log sections in /etc/logrotate.d/radiusd. By keeping SELinux in "Enforcing" mode, radiusd user will be limited in the directories he can write to.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 24, 2019
Updated Aug 4, 2024
Reserved Mar 27, 2019
CISA Vulnrichment
Updated Aug 1, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 1, 2019