{"id":"UBUNTU-CVE-2019-11675","details":"The groonga-httpd package 6.1.5-1 for Debian sets the /var/log/groonga ownership to the groonga account, which might let local users obtain root access because of unsafe interaction with logrotate. For example, an attacker can exploit a race condition to insert a symlink from /var/log/groonga/httpd to /etc/bash_completion.d. NOTE: this is an issue in the Debian packaging of the Groonga HTTP server.","modified":"2026-04-22T12:07:35.356714Z","published":"2019-05-02T06:29:00Z","upstream":["CVE-2019-11675"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2019-11675"},{"type":"REPORT","url":"https://bugs.debian.org/928304"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2019-11675"}],"affected":[{"package":{"name":"groonga","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/groonga@6.0.1-1ubuntu1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.0.6.1-2ubuntu2","4.0.6.1-2ubuntu3","5.1.1-1ubuntu2","5.1.2-1ubuntu1","6.0.0-1ubuntu2","6.0.1-1ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"groonga","binary_version":"6.0.1-1ubuntu1"},{"binary_name":"groonga-bin","binary_version":"6.0.1-1ubuntu1"},{"binary_name":"groonga-examples","binary_version":"6.0.1-1ubuntu1"},{"binary_name":"groonga-httpd","binary_version":"6.0.1-1ubuntu1"},{"binary_name":"groonga-munin-plugins","binary_version":"6.0.1-1ubuntu1"},{"binary_name":"groonga-plugin-suggest","binary_version":"6.0.1-1ubuntu1"},{"binary_name":"groonga-server-common","binary_version":"6.0.1-1ubuntu1"},{"binary_version":"6.0.1-1ubuntu1","binary_name":"groonga-server-gqtp"},{"binary_version":"6.0.1-1ubuntu1","binary_name":"groonga-token-filter-stem"},{"binary_name":"groonga-tokenizer-mecab","binary_version":"6.0.1-1ubuntu1"},{"binary_name":"libgroonga0","binary_version":"6.0.1-1ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-11675.json"}},{"package":{"name":"groonga","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/groonga@8.0.0-1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.0.6-1","7.0.8-1","7.0.9-1","7.1.0-1","7.1.1-1","7.1.1-1build1","8.0.0-1"],"ecosystem_specific":{"binaries":[{"binary_name":"groonga","binary_version":"8.0.0-1"},{"binary_name":"groonga-bin","binary_version":"8.0.0-1"},{"binary_name":"groonga-examples","binary_version":"8.0.0-1"},{"binary_name":"groonga-httpd","binary_version":"8.0.0-1"},{"binary_name":"groonga-munin-plugins","binary_version":"8.0.0-1"},{"binary_name":"groonga-plugin-suggest","binary_version":"8.0.0-1"},{"binary_version":"8.0.0-1","binary_name":"groonga-server-common"},{"binary_name":"groonga-server-gqtp","binary_version":"8.0.0-1"},{"binary_name":"groonga-token-filter-stem","binary_version":"8.0.0-1"},{"binary_name":"groonga-tokenizer-mecab","binary_version":"8.0.0-1"},{"binary_name":"libgroonga0","binary_version":"8.0.0-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-11675.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}